Cross-site scripting in ThinkAdmin
Moderate severity
GitHub Reviewed
Published
May 6, 2021
to the GitHub Advisory Database
•
Updated May 15, 2025
Description
Published by the National Vulnerability Database
Dec 1, 2020
Reviewed
Apr 9, 2021
Published to the GitHub Advisory Database
May 6, 2021
Last updated
May 15, 2025
ThinkAdmin version v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
References