Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
onethink onethink 1.1 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2017-14323
SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote malicious users to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.
Onethink Onethink 1.1
Onethink Onethink 1.0
8.8
CVSSv3
CVE-2018-15197
An issue exists in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator privileges.
Onethink Onethink 1.1
8.8
CVSSv3
CVE-2018-15198
An issue exists in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user.
Onethink Onethink 1.1
NA
CVE-2024-33444
SQL injection vulnerability in onethink v.1.1 allows a remote malicious user to escalate privileges via a crafted script to the ModelModel.class.php component.
NA
CVE-2024-33443
An issue in onethink v.1.1 allows a remote malicious user to execute arbitrary code via a crafted script to the AddonsController.class.php component.
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started