Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

1Dreamgn

#15392de 53,639
17.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2023-31019
8.8
2023-12-04
Unknown · Thinkadmin · CVE-2023-48965
**Name of the Vulnerable Software and Affected Versions** ThinkAdmin version 6.1.53 **Description** An issue in the component /admin/api.plugs/script allows attackers to getshell via providing a crafted URL to download a malicious PHP file. **Recommendations** For ThinkAdmin version 6.1.53, as a temporary workaround, consider restricting access to the /admin/api.plugs/script component until a patch is available. Avoid using crafted URLs that could lead to downloading malicious PHP files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-31020
8.8
2023-12-04
Unknown · Thinkadmin · CVE-2023-48966
**Name of the Vulnerable Software and Affected Versions** ThinkAdmin version 6.1.53 **Description** An arbitrary file upload issue in the `/admin/api.upload/file` component allows attackers to execute arbitrary code via a crafted Zip file. **Recommendations** For ThinkAdmin version 6.1.53, consider disabling the `/admin/api.upload/file` component until a patch is available to prevent arbitrary file uploads and subsequent code execution. Restrict access to this component to minimize the risk of exploitation. Avoid using this component with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.