Loading HuntDB...

GHSA-7gq9-p94f-g5v9

GitHub Security Advisory

ThinkAdmin arbitrary file upload vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a crafted Zip file.

Affected Packages

Packagist zoujingli/thinkadmin
Affected versions: 0 (last affected: 6.1.53)

Related CVEs

Key Information

GHSA ID
GHSA-7gq9-p94f-g5v9
Published
December 4, 2023 6:30 PM
Last Modified
December 8, 2023 9:57 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
zoujingli/thinkadmin
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.