Thinksaas · Thinksaas · CVE-2018-15130
**Name of the Vulnerable Software and Affected Versions**
ThinkSAAS versions prior to 2018-07-25
**Description**
The issue allows for XSS via the `index.php?app=group&ac=create&ts=do` endpoint, specifically through the `groupdesc` parameter.
**Recommendations**
For versions prior to 2018-07-25, avoid using the `groupdesc` parameter in the `index.php?app=group&ac=create&ts=do` endpoint until the issue is resolved.