Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Thinksaas Subscribe
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-18741 1 Thinksaas 1 Thinksaas 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app=photo."
CVE-2020-35337 1 Thinksaas 1 Thinksaas 2021-03-24 7.5 HIGH 9.8 CRITICAL
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.
CVE-2019-16664 1 Thinksaas 1 Thinksaas 2019-09-23 3.5 LOW 4.8 MEDIUM
An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
CVE-2019-16665 1 Thinksaas 1 Thinksaas 2019-09-23 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBED element.
CVE-2018-15130 1 Thinksaas 1 Thinksaas 2018-10-05 3.5 LOW 5.4 MEDIUM
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
CVE-2018-15129 1 Thinksaas 1 Thinksaas 2018-10-05 3.5 LOW 5.4 MEDIUM
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.