{"id":"GHSA-969f-v7jv-pgj3","summary":"ThinkPHP Cross-Site Scripting Vulnerability","details":"ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.","aliases":["CVE-2024-34467"],"modified":"2024-08-16T22:21:29.138911Z","published":"2024-05-04T21:30:33Z","database_specific":{"github_reviewed_at":"2024-05-06T14:24:22Z","nvd_published_at":"2024-05-04T20:15:07Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34467"},{"type":"WEB","url":"https://github.com/top-think/framework/issues/2996"},{"type":"WEB","url":"https://github.com/top-think/framework/commit/403358cd3e510e2fdab63f951930bdd093314eee"},{"type":"WEB","url":"https://github.com/top-think/framework/commit/57d1950a1844ef8d3098ea290032aeb92e2e32c3"},{"type":"WEB","url":"https://github.com/top-think/framework/commit/d3904e51e279c3b72ee206192aeccf9b1cffb534"},{"type":"PACKAGE","url":"https://github.com/top-think/framework"}],"affected":[{"package":{"name":"topthink/framework","ecosystem":"Packagist","purl":"pkg:composer/topthink/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.4"}]}],"versions":["v8.0.0","v8.0.1","v8.0.2","v8.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-969f-v7jv-pgj3/GHSA-969f-v7jv-pgj3.json"}},{"package":{"name":"topthink/framework","ecosystem":"Packagist","purl":"pkg:composer/topthink/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.5"}]}],"versions":["v6.1.0","v6.1.1","v6.1.2","v6.1.3","v6.1.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-969f-v7jv-pgj3/GHSA-969f-v7jv-pgj3.json"}},{"package":{"name":"topthink/framework","ecosystem":"Packagist","purl":"pkg:composer/topthink/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.17"}]}],"versions":["5.0","5.0-rc1","5.0-rc2","5.0-rc3","5.0-rc4","v5.0.1","v5.0.10","v5.0.11","v5.0.12","v5.0.13","v5.0.14","v5.0.15","v5.0.16","v5.0.17","v5.0.18","v5.0.19","v5.0.2","v5.0.20","v5.0.21","v5.0.22","v5.0.23","v5.0.24","v5.0.25","v5.0.3","v5.0.4","v5.0.5","v5.0.6","v5.0.7","v5.0.8","v5.0.9","v5.1-beta.1","v5.1-rc.1","v5.1-rc.2","v5.1-rc.3","v5.1.0","v5.1.1","v5.1.10","v5.1.11","v5.1.12","v5.1.13","v5.1.14","v5.1.15","v5.1.16","v5.1.17","v5.1.18","v5.1.19","v5.1.2","v5.1.20","v5.1.21","v5.1.22","v5.1.23","v5.1.24","v5.1.25","v5.1.26","v5.1.27","v5.1.28","v5.1.29","v5.1.3","v5.1.30","v5.1.31","v5.1.32","v5.1.33","v5.1.34","v5.1.35","v5.1.36","v5.1.37","v5.1.37.1","v5.1.38","v5.1.38.1","v5.1.39","v5.1.4","v5.1.40","v5.1.41","v5.1.42","v5.1.5","v5.1.6","v5.1.7","v5.1.8","v5.1.9","v5.2-beta.2","v5.2-beta.3","v5.2-rc1","v6.0.0","v6.0.0-rc2","v6.0.0-rc3","v6.0.0-rc4","v6.0.0-rc5","v6.0.1","v6.0.10","v6.0.11","v6.0.12","v6.0.13","v6.0.14","v6.0.15","v6.0.16","v6.0.2","v6.0.3","v6.0.4","v6.0.5","v6.0.6","v6.0.7","v6.0.8","v6.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-969f-v7jv-pgj3/GHSA-969f-v7jv-pgj3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}