Skip to content
Noroxi

thinkadmin records

9 published records for vendor thinkadmin.

All records

9 records
  • ThinkAdmin v6 is affected by a directory traversal vulnerability.

    HighCVSS 7.5Proof of conceptEPSS 75%

    thinkadmin · thinkadminSep 14, 2020

  • An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/w

    CriticalCVSS 9.8No exploitEPSS 4%

    thinkadmin · thinkadminJan 13, 2021

  • application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after

    CriticalCVSS 9.8No exploitEPSS 1%

    thinkadmin · thinkadminApr 8, 2019

  • An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary c

    HighCVSS 8.8No exploitEPSS 1%

    thinkadmin · thinkadminDec 4, 2023

  • An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download

    HighCVSS 8.8No exploitEPSS 1%

    thinkadmin · thinkadminDec 4, 2023

  • ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.

    HighCVSS 7.5No exploitEPSS 2%

    thinkadmin · thinkadminMar 3, 2021

  • An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a cr

    MediumCVSS 6.1No exploitEPSS 1%

    thinkadmin · thinkadminJun 15, 2023

  • ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.

    MediumCVSS 5.4No exploitEPSS 1%

    thinkadmin · thinkadminDec 1, 2020

  • ThinkAdmin Plugs.php script deserialization

    LowCVSS 2.3No exploitEPSS 1%

    thinkadmin · thinkadminNov 3, 2024