Record summary

CVE-2020-25540 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit, 4 repository PoCs, and 1 Nuclei template.

Description

ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET request encode parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 21, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
4
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub Advisory6.0affected

Proofs of concept

5

Catalogued exploits

ExploitDBThinkAdmin 6 - Arbitrarily File ReadExploitDB exploitby HzllagaNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubSchira4396/CVE-2020-25540Repository PoCby Schira4396Stars: 7Not analyzed3 files

2.6 KiB

GitHub

PoC details
GitHubRajChowdhury240/ThinkAdmin-CVE-2020-25540Repository PoCby RajChowdhury240Stars: 1Not analyzed2 files

1.3 KiB

GitHub

PoC details
GitHublowkey0808/cve-2020-25540Repository PoCby lowkey0808Stars: 0Not analyzed2 files

2.0 KiB

GitHub

PoC details
GitHubsimonlee-hello/CVE-2020-25540Repository PoCby simonlee-helloStars: 0Not analyzed2 files

5.2 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHThinkAdmin 6 - Local File InclusionCVSS 7.5

ThinkAdmin version 6 is affected by a local file inclusion vulnerability because an unauthorized attacker can read arbitrary files on a remote server via GET request encode parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.

Remediation

Apply the latest patch or upgrade to a version that is not affected by the vulnerability.

WeaknessesCWE-22
Authorsgeeknik
Template tagscvecve2020thinkadminlfiedbpacketstormctologvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:thinkadmin:thinkadmin:6.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6