First published: Sun Jul 21 2024(Updated: )
A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of the file app/system/action/anti.php of the component Admin Panel Security Center. The manipulation of the argument ip/email/phone leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272064.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thinksaas | =3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6942 is classified as a problematic vulnerability.
CVE-2024-6942 is a cross-site scripting vulnerability affecting the Admin Panel Security Center.
CVE-2024-6942 allows attackers to manipulate input arguments leading to potential cross-site scripting attacks.
To resolve CVE-2024-6942, it is recommended to validate and sanitize inputs for the affected functions in the Admin Panel.
CVE-2024-6942 affects ThinkSAAS version 3.7.0.