MEDIUM5.4
GHSA-v47f-vp3p-5j6h
Cross-site scripting in ThinkAdmin
Quick fix
GHSA-v47f-vp3p-5j6h — zoujingli/thinkadmin: upgrade to the fixed version with the command below.
composer require zoujingli/thinkadmin:^6.0.22Details
ThinkAdmin version v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zoujingli/thinkadmin
Introduced in:
0Fixed in: 6.0.22Fix
composer require zoujingli/thinkadmin:^6.0.22