Known Vulnerabilities for products from Thinksaas
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Thinksaas".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-35337 json | ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter... | 9.8 - CRITICAL | 2021-03-24 | 2021-03-24 |
| CVE-2020-18741 json | Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photo... | 5.3 - MEDIUM | 2021-07-08 | 2022-07-12 |
| CVE-2019-16665 json | An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI,... | 6.1 - MEDIUM | 2019-09-21 | 2019-09-23 |
| CVE-2019-16664 json | An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter. | 4.8 - MEDIUM | 2019-09-21 | 2019-09-23 |
| CVE-2018-15130 json | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter. | 5.4 - MEDIUM | 2018-08-07 | 2018-10-05 |
| CVE-2018-15129 json | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter. | 5.4 - MEDIUM | 2018-08-07 | 2018-10-05 |
Known software with vulnerabilities from Thinksaas
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Thinksaas | Thinksaas | 2.6 |