{"id":"CVE-2020-20120","details":"ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the \"where\" and \"query\" methods.","aliases":["GHSA-m7h5-fjjq-559f"],"modified":"2026-07-09T00:21:39.770563Z","published":"2021-09-28T23:15:07.007Z","references":[{"type":"EVIDENCE","url":"https://github.com/top-think/thinkphp/issues/553"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/top-think/thinkphp","events":[{"introduced":"0"},{"last_affected":"94d5c5ef980be6a3f31d6938e5cbf997f6cdb4a2"}],"database_specific":{"cpe":"cpe:2.3:a:thinkphp:thinkphp:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.2.3"}],"source":"CPE_RANGE"}}],"versions":["3.2.3","3.2.2","3.2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-20120.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}