The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-PHP-TOPTHINKFRAMEWORK-2385695 | third party advisory |
https://github.com/top-think/framework/releases/tag/v6.0.12 | third party advisory |
https://github.com/top-think/framework/commit/d3b5aeae94bc71bae97977d05cd12c3e0550905c | third party advisory patch |