A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the word parameter.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/thinksaas/ThinkSAAS/issues/34 |
|
History
Wed, 25 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:thinksaas:thinksaas:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Wed, 23 Apr 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinksaas
Thinksaas thinksaas |
|
| CPEs | cpe:2.3:a:thinksaas:thinksaas:3.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Thinksaas
Thinksaas thinksaas |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T02:27:53.548Z
Reserved: 2024-04-23T00:00:00.000Z
Link: CVE-2024-33101
Updated: 2024-08-02T02:27:53.548Z
Status : Analyzed
Published: 2024-04-30T18:15:19.797
Modified: 2025-04-23T01:33:24.147
Link: CVE-2024-33101
No data.
OpenCVE Enrichment
No data.
Weaknesses