zoujingli/ThinkAdmin

zoujingli/ThinkAdmin

Releases15
Frequency2 months 2 weeks
Last Release
Stars2.26K
基于 ThinkPHP6&8 的极简后台管理系统,内置注解权限、异步多任务、应用插件生态等,支持类 PaaS 更新公共模块和应用插件,插件可本地化定制开发。

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.

9.8 CRITICAL7.5 HIGH

An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary remote code execution.

5.4 MEDIUM4.3 MEDIUM

ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.

7.5 HIGH5 MEDIUM

ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET request encode parameter.

5 MEDIUM

application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change.