thinkadmin records
9 published records for vendor thinkadmin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 22.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-502 Deserialization of Untrusted Data2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2020-25540Proof of concept | ThinkAdmin v6 is affected by a directory traversal vulnerability.thinkadmin · thinkadmin · CWE-22 | High7.5 | — | 75.3% | Sep 14, 2020 |
40Plan | CVE-2020-23653No exploit | An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wthinkadmin · thinkadmin · CWE-502 | Critical9.8 | — | 4.1% | Jan 13, 2021 |
39Monitor | CVE-2019-11018No exploit | application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials afterthinkadmin · thinkadmin · CWE-287 | Critical9.8 | — | 1.4% | Apr 8, 2019 |
35Monitor | CVE-2023-48966No exploit | An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary cthinkadmin · thinkadmin · CWE-434 | High8.8 | — | 1.1% | Dec 4, 2023 |
35Monitor | CVE-2023-48965No exploit | An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to downloadthinkadmin · thinkadmin · CWE-434 | High8.8 | — | 0.9% | Dec 4, 2023 |
31Monitor | CVE-2020-35296No exploit | ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.thinkadmin · thinkadmin · CWE-798 | High7.5 | — | 2.2% | Mar 3, 2021 |
24Monitor | CVE-2023-34833No exploit | An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crthinkadmin · thinkadmin · CWE-434 | Medium6.1 | — | 0.5% | Jun 15, 2023 |
21Monitor | CVE-2020-29315No exploit | ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.thinkadmin · thinkadmin · CWE-79 | Medium5.4 | — | 1.0% | Dec 1, 2020 |
9Monitor | CVE-2024-10749No exploit | ThinkAdmin Plugs.php script deserializationthinkadmin · thinkadmin · CWE-502 | Low2.3 | — | 0.5% | Nov 3, 2024 |
- CVE-2020-2554053Plan
ThinkAdmin v6 is affected by a directory traversal vulnerability.
HighCVSS 7.5Proof of conceptEPSS 75%thinkadmin · thinkadminSep 14, 2020
- CVE-2020-2365340Plan
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/w
CriticalCVSS 9.8No exploitEPSS 4%thinkadmin · thinkadminJan 13, 2021
- CVE-2019-1101839Monitor
application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after
CriticalCVSS 9.8No exploitEPSS 1%thinkadmin · thinkadminApr 8, 2019
- CVE-2023-4896635Monitor
An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary c
HighCVSS 8.8No exploitEPSS 1%thinkadmin · thinkadminDec 4, 2023
- CVE-2023-4896535Monitor
An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download
HighCVSS 8.8No exploitEPSS 1%thinkadmin · thinkadminDec 4, 2023
- CVE-2020-3529631Monitor
ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.
HighCVSS 7.5No exploitEPSS 2%thinkadmin · thinkadminMar 3, 2021
- CVE-2023-3483324Monitor
An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a cr
MediumCVSS 6.1No exploitEPSS 1%thinkadmin · thinkadminJun 15, 2023
- CVE-2020-2931521Monitor
ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
MediumCVSS 5.4No exploitEPSS 1%thinkadmin · thinkadminDec 1, 2020
- CVE-2024-107499Monitor
ThinkAdmin Plugs.php script deserialization
LowCVSS 2.3No exploitEPSS 1%thinkadmin · thinkadminNov 3, 2024