CVE-2024-6942
- EPSS 0.13%
- Veröffentlicht 21.07.2024 07:15:05
- Zuletzt bearbeitet 13.11.2025 17:58:47
A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of the file app/system/action/anti.php of the component Admin Panel Security Center. The manipulation of the argument ip/email/phone l...
CVE-2024-6941
- EPSS 0.13%
- Veröffentlicht 21.07.2024 06:15:05
- Zuletzt bearbeitet 13.11.2025 16:14:30
A vulnerability, which was classified as problematic, has been found in ThinkSAAS 3.7.0. This issue affects some unknown processing of the file app/system/action/do.php. The manipulation of the argument site_title/site_subtitle/site_key/site_desc/sit...
CVE-2024-40455
- EPSS 0.13%
- Veröffentlicht 16.07.2024 20:15:03
- Zuletzt bearbeitet 28.04.2025 14:44:33
An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.
CVE-2024-40456
- EPSS 0.26%
- Veröffentlicht 16.07.2024 20:15:03
- Zuletzt bearbeitet 28.04.2025 14:43:04
ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.
CVE-2024-33101
- EPSS 0.71%
- Veröffentlicht 30.04.2024 18:15:19
- Zuletzt bearbeitet 23.04.2025 01:33:24
A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the word parameter.
CVE-2024-33102
- EPSS 0.92%
- Veröffentlicht 30.04.2024 18:15:19
- Zuletzt bearbeitet 23.04.2025 01:35:46
A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the code parameter.
CVE-2020-18741
- EPSS 0.24%
- Veröffentlicht 08.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:45
Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app=photo."
CVE-2020-35337
- EPSS 0.53%
- Veröffentlicht 24.03.2021 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:27:11
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.
CVE-2019-16664
- EPSS 0.22%
- Veröffentlicht 21.09.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:55
An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
CVE-2019-16665
- EPSS 0.22%
- Veröffentlicht 21.09.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:56
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBED element.