{"id":"CVE-2021-44892","details":"A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.","aliases":["GHSA-75jp-87w2-c6x2"],"modified":"2026-07-09T00:37:59.069646Z","published":"2022-02-10T17:15:09.330Z","references":[{"type":"REPORT","url":"https://github.com/Stakcery/Web-Security/issues/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/top-think/thinkphp","events":[{"introduced":"94d5c5ef980be6a3f31d6938e5cbf997f6cdb4a2"},{"last_affected":"94d5c5ef980be6a3f31d6938e5cbf997f6cdb4a2"}],"database_specific":{"cpe":"cpe:2.3:a:thinkphp:thinkphp:3.2.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.2.3"},{"last_affected":"3.2.3"}],"source":"CPE_STRING"}}],"versions":["3.2.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44892.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}