ThinkPHP /index.php 信息泄露漏洞(CVE-2022-25481)

2025-08-21 ThinkPHP PoC No

Description

ThinkPHP是中国顶想信息科技公司开发的一款基于PHP的开源轻量级Web应用程序开发框架。ThinkPHP 5.0.24版本由于未正确配置PATHINFO参数,攻击者可以通过访问index.php获取系统环境参数,从而可能导致敏感信息泄露、数据篡改或执行未授权操作。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities