{"id":"CVE-2018-18546","details":"ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.","aliases":["GHSA-j7g8-3qqg-8cvm"],"modified":"2026-07-08T17:16:52.270104Z","published":"2018-10-21T01:29:00.433Z","references":[{"type":"FIX","url":"https://github.com/top-think/thinkphp/commit/9748cb80d2f24c89218f358ca2f5ab88ee33396f"},{"type":"EVIDENCE","url":"https://98587329.github.io/2018/10/09/thinkphp%E6%B3%A8%E5%85%A5%E5%88%86%E6%9E%90/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/top-think/thinkphp","events":[{"introduced":"728c0fc21e9b438b930b916a8257a25ea9ffaf79"},{"last_affected":"728c0fc21e9b438b930b916a8257a25ea9ffaf79"},{"fixed":"9748cb80d2f24c89218f358ca2f5ab88ee33396f"}],"database_specific":{"cpe":"cpe:2.3:a:thinkphp:thinkphp:3.2.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.2.4"},{"last_affected":"3.2.4"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["3.2.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18546.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}