Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aaaqingwu

#47789of 53,634
5.3Total CVSS
Vulnerabilities · 1
PT-2021-10232
5.3
2021-07-08
Thinksaas · Thinksaas · CVE-2020-18741
Name of the Vulnerable Software and Affected Versions: ThinkSAAS version 2.7 Description: The issue allows remote attackers to modify the description of any user's photo. This is achieved via the `photoid[]` and `photodesc[]` parameters in the "index.php?app=photo" component. Recommendations: For ThinkSAAS version 2.7, as a temporary workaround, consider restricting access to the "index.php?app=photo" component until a patch is available. Avoid using the `photoid[]` and `photodesc[]` parameters in this component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.