Vulnerability Description
Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app=photo."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thinksaas | Thinksaas | 2.7 |
References
- https://github.com/thinksaas/ThinkSAAS/issues/19ExploitIssue TrackingThird Party Advisory
- https://github.com/thinksaas/ThinkSAAS/issues/19ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-18741?
CVE-2020-18741 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "photodesc%5B%5D" parameters in the component "index.php?app=...
How severe is CVE-2020-18741?
CVE-2020-18741 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-18741?
Check the references section above for vendor advisories and patch information. Affected products include: Thinksaas Thinksaas.