Security Advisory

CVE-2018-18546

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-10-21 01:00:00
Last updated 2024-09-17 00:22:01
Assigner mitre
State PUBLISHED

Description

ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.