PT-2024-37980 · Thinksaas · Thinksaas
Jiashenghe
·
Published
2024-07-21
·
Updated
2024-09-20
·
CVE-2024-6942
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ThinkSAAS version 3.7.0
Description
A problematic issue was found in the Admin Panel Security Center component, specifically in the file app/system/action/anti.php. The manipulation of the
ip, email, or phone argument leads to cross-site scripting. This issue can be exploited remotely.Recommendations
For ThinkSAAS version 3.7.0, consider disabling the affected function in the app/system/action/anti.php file as a temporary workaround until a patch is available. Restrict access to the Admin Panel Security Center to minimize the risk of exploitation. Avoid using the
ip, email, or phone arguments in the affected component until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thinksaas