S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-47945 Scanner

CVE-2022-47945 scanner - Local File Inclusion (LFI) vulnerability in ThinkPHP Framework

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-47945
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The ThinkPHP Framework is a popular open-source PHP web application framework designed for quick and efficient development. The framework is widely recognized for its robustness and flexibility regarding building scalable and high-performance web applications. This framework is widely used by developers worldwide and has a massive community of developers that contribute to its development and maintenance. ThinkPHP Framework provides a comprehensive solution for web development, including database operations, template parsing, caching, HTTP requests, and many more.

The CVE-2022-47945 vulnerability is a serious security flaw that has been detected in the ThinkPHP Framework earlier than 6.0.14 versions. The vulnerability allows an unauthenticated and remote attacker to execute arbitrary operating system commands by exploiting the language pack feature. The attacker can manipulate the lang parameter if the language pack feature is enabled (lang_switch_on=true), leading to local file inclusion. Malicious actors can exploit this vulnerability to run system commands remotely on vulnerable web applications, take control over the system, and steal sensitive data.

Exploiting this vulnerability can cause severe consequences. Attackers can launch a wide range of attacks against unsecured systems, including front door attacks, backdoor attacks, and privilege escalation attacks. In some cases, attackers may even be able to gain full system access and take complete control of the targeted system. Attackers can also steal sensitive data, including usernames, passwords, and other confidential information, causing severe damage to businesses.

In conclusion, cyber threats are increasing day by day, and it is crucial to be aware of the latest vulnerabilities and stay well informed about the risks to digital assets. s4e.io provides pro features that allow users to get detailed information about the vulnerabilities present in their digital assets. By subscribing to s4e.io, individuals can keep themselves well protected against cyber threats and enjoy peace of mind.

 

REFERENCES

Solution Advice

Developers can take several precautions to protect against this vulnerability, including:

  • Update to the latest version of the ThinkPHP framework, which has patched this vulnerability.
  • Disable the language pack feature if it's not in use.
  • Implement input validation and output encoding for user input.
  • Isolate the web application in a secure environment with limited access to the system.
  • Implement intrusion detection systems and web application firewalls to prevent attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-47945 scanner - Local File Inclusion (LFI) vulnerability in ThinkPHP Framework | S4E