Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2023-48966

Disclosure Date: December 04, 2023 (last updated December 08, 2023)
An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a crafted Zip file.
Attacker Value
Unknown

CVE-2023-48965

Disclosure Date: December 04, 2023 (last updated December 08, 2023)
An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malicious PHP file.