CRITICAL

CVE-2022-33107

CVSS v3

9.8

CRITICAL

EPSS Score

20.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\\league\\flysystem-cached-adapter\\src\\Storage\\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

Technical details

Published
6/29/2022

Frequently asked questions

What is CVE-2022-33107?

ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\\league\\flysystem-cached-adapter\\src\\Storage\\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

Is CVE-2022-33107 actively exploited?

Active exploitation of CVE-2022-33107 has not been confirmed. The EPSS score is 20.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-33107?

CVE-2022-33107 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-33107 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.