Thinksaas

Thinksaas

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Veröffentlicht 21.07.2024 07:15:05
  • Zuletzt bearbeitet 13.11.2025 17:58:47

A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of the file app/system/action/anti.php of the component Admin Panel Security Center. The manipulation of the argument ip/email/phone l...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 21.07.2024 06:15:05
  • Zuletzt bearbeitet 13.11.2025 16:14:30

A vulnerability, which was classified as problematic, has been found in ThinkSAAS 3.7.0. This issue affects some unknown processing of the file app/system/action/do.php. The manipulation of the argument site_title/site_subtitle/site_key/site_desc/sit...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 16.07.2024 20:15:03
  • Zuletzt bearbeitet 28.04.2025 14:44:33

An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 16.07.2024 20:15:03
  • Zuletzt bearbeitet 28.04.2025 14:43:04

ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.

Exploit
  • EPSS 0.71%
  • Veröffentlicht 30.04.2024 18:15:19
  • Zuletzt bearbeitet 23.04.2025 01:33:24

A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the word parameter.

Exploit
  • EPSS 0.92%
  • Veröffentlicht 30.04.2024 18:15:19
  • Zuletzt bearbeitet 23.04.2025 01:35:46

A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the code parameter.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 08.07.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:08:45

Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app=photo."

Exploit
  • EPSS 0.53%
  • Veröffentlicht 24.03.2021 16:15:15
  • Zuletzt bearbeitet 21.11.2024 05:27:11

ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 21.09.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:30:55

An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 21.09.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:30:56

An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBED element.