VYPR
High severity8.8NVD Advisory· Published Dec 6, 2022· Updated Jun 17, 2026

CVE-2022-44289

CVE-2022-44289

Description

Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
topthink/frameworkPackagist
<= 5.0.24
topthink/frameworkPackagist
>= 5.1, <= 5.1.41

Affected products

4
  • Thinkphp/Thinkphp3 versions
    cpe:2.3:a:thinkphp:thinkphp:5.0.24:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:thinkphp:thinkphp:5.0.24:*:*:*:*:*:*:*
    • cpe:2.3:a:thinkphp:thinkphp:5.1.41:*:*:*:*:*:*:*
    • (no CPE)
  • ghsa-coords
    Range: <= 5.0.24

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.