A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of the file app/system/action/anti.php of the component Admin Panel Security Center. The manipulation of the argument ip/email/phone leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272064.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47928 | A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of the file app/system/action/anti.php of the component Admin Panel Security Center. The manipulation of the argument ip/email/phone leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272064. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:thinksaas:thinksaas:3.70:*:*:*:*:*:*:* |
Fri, 20 Sep 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinksaas
Thinksaas thinksaas |
|
| CPEs | cpe:2.3:a:thinksaas:thinksaas:3.7.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Thinksaas
Thinksaas thinksaas |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-01T21:45:38.332Z
Reserved: 2024-07-20T09:45:51.556Z
Link: CVE-2024-6942
Updated: 2024-08-01T21:45:38.332Z
Status : Analyzed
Published: 2024-07-21T07:15:05.887
Modified: 2025-11-13T17:58:47.840
Link: CVE-2024-6942
No data.
OpenCVE Enrichment
No data.
EUVD