Headline
GHSA-4847-gqxx-v9xp: ThinkCMF Cross-site Scripting Vulnerability
Cross Site Scripting (XSS) vulnerability in UserController.php
in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login
.
ThinkCMF Cross-site Scripting Vulnerability
Moderate severity GitHub Reviewed Published Aug 11, 2023 to the GitHub Advisory Database • Updated Aug 11, 2023
Related news
CVE-2020-25915: There is a store Stored XSS vulnerability in user management · Issue #675 · thinkcmf/thinkcmf
Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.