Overview
- Description
- A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Source
- cna@vuldb.com
- NVD status
- Analyzed
Risk scores
CVSS 4.0
- Type
- Secondary
- Base score
- 2.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- LOW
CVSS 3.1
- Type
- Primary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Secondary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:N/AC:H/Au:S/C:P/I:P/A:P
Weaknesses
- cna@vuldb.com
- CWE-502
Social media
- Hype score
- Not currently trending
CVE-2024-10749 A vulnerability, which was classified as critical, was fo... https://t.co/BCJvz2qs4p Don't wait vulnerability scanning results: https://t.co/oh1APvMMnd
@VulmonFeeds
4 Nov 2024
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
馃毃 CVE-2024-10749: Critical deserialization vuln in ThinkAdmin <=6.1.67 Plugs.php script uptoken. Impacts: RCE, data theft. Action: Patch immediately or isolate affected systems. Exploit available! #CyberSecurity #InfoSec
@oktsec
3 Nov 2024
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:thinkadmin:thinkadmin:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE5A0947-30AD-4012-89BA-DEE70CBCCA1B", "versionEndIncluding": "6.1.67", "versionStartIncluding": "6.0" } ], "operator": "OR" } ] } ]