Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2020-25915
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.
0
Attacker Value
Unknown
CVE-2022-40849
Disclosure Date: December 01, 2022 (last updated October 08, 2023)
ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).
0
Attacker Value
Unknown
CVE-2022-40489
Disclosure Date: December 01, 2022 (last updated October 08, 2023)
ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.
0
Attacker Value
Unknown
CVE-2021-40616
Disclosure Date: June 14, 2022 (last updated October 07, 2023)
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.
0
Attacker Value
Unknown
CVE-2020-20601
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
0
Attacker Value
Unknown
CVE-2020-18151
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.
0
Attacker Value
Unknown
CVE-2019-7580
Disclosure Date: February 07, 2019 (last updated November 27, 2024)
ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.
0
Attacker Value
Unknown
CVE-2019-6713
Disclosure Date: January 23, 2019 (last updated November 27, 2024)
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.
0
Attacker Value
Unknown
CVE-2018-19897
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via the listorders[key][1] parameter in a Link listorders action.
0
Attacker Value
Unknown
CVE-2018-19894
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager privilege via the ids[] parameter in a commentadmin action.
0