VYPR
Critical severity9.8NVD Advisory· Published Feb 8, 2023· Updated Jun 17, 2026

CVE-2022-45982

CVE-2022-45982

Description

thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
topthink/thinkPackagist
<= 6.1.1

Affected products

4
  • Thinkphp/Thinkphp3 versions
    cpe:2.3:a:thinkphp:thinkphp:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:thinkphp:thinkphp:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.13
    • cpe:2.3:a:thinkphp:thinkphp:6.1.0:*:*:*:*:*:*:*
    • (no CPE)
  • ghsa-coords
    Range: <= 6.1.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.