S4E just found an informational finding from tcp full port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-25481

7.5
CVSSmedium
Requires local system access · no authentication required.
Description

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

Attack Vector
Local
Privileges Req.
None
User Interaction
None
thinkphp
Updated Sep 28, 2026View on NVD →
S4E scanner

CVE history: thinkphp

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →