ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| thinkcmf/thinkcmf(Packagist) | 0 | 6.0.8 | N/A |
CVSS Metrics