ThinkSAAS do.php cross site scripting
Published Jul 21, 2024
5.3
MEDIUMCVSS 4.0
EPSS 0.44%
Description
A vulnerability, which was classified as problematic, has been found in ThinkSAAS 3.7.0. This issue affects some unknown processing of the file app/system/action/do.php. The manipulation of the argument site_title/site_subtitle/site_key/site_desc/site_url/site_email/site_icp leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272063.
Affected products
- Vendor n/a Product ThinkSAAS Defaultn/a
- Version 3.7.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | ThinkSAAS | n/a |
|
-
- Version 3.7.0StatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://github.com/thinksaas/ThinkSAAS/issues/36 exploitissue-trackingIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.272063 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.272063 vdb-entrytechnical-descriptionThird Party Advisory
- https://vuldb.com/?submit.373282 third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/thinksaas/ThinkSAAS/issues/36 | exploitissue-trackingIssue TrackingThird Party Advisory | |
| https://vuldb.com/?ctiid.272063 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.272063 | vdb-entrytechnical-descriptionThird Party Advisory | |
| https://vuldb.com/?submit.373282 | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.