QID 994818
Date Published: 2023-08-14
QID 994818: PHP (Composer) Security Update for thinkcmf/thinkcmf (GHSA-4847-gqxx-v9xp)
Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4847-gqxx-v9xp for updates and patch information.
Vendor References
- GHSA-4847-gqxx-v9xp -
github.com/advisories/GHSA-4847-gqxx-v9xp
CVEs related to QID 994818
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4847-gqxx-v9xp | thinkcmf/thinkcmf |
|