Onethink

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    2
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-33443

    An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.

    Last Modified: Apr 16, 2025
    Published: Apr 29, 2024

    CVE-2024-33444

    SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.

    Last Modified: Apr 16, 2025
    Published: Apr 29, 2024

    CVE-2018-16449

    OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html.

    Last Modified: Nov 21, 2024
    Published: Sep 04, 2018

    CVE-2018-15197

    An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator privileges.

    Last Modified: Nov 21, 2024
    Published: Aug 08, 2018

    CVE-2018-15198

    An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user.

    Last Modified: Nov 21, 2024
    Published: Aug 08, 2018
    Items Per Page
    Onethink Vulnerabilities & Security CVEs | CVE-DB