High severity8.8NVD Advisory· Published Feb 10, 2022· Updated Jun 17, 2026
CVE-2021-44892
CVE-2021-44892
Description
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
topthink/frameworkPackagist | <= 3.2.3 | — |
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/Stakcery/Web-Security/issues/1nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-75jp-87w2-c6x2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-44892ghsaADVISORY
News mentions
0No linked articles in our index yet.