File Upload Vulnerability in ThinkDashboard by MatiasDesuu
CVE-2025-64176
5.3MEDIUM
What is CVE-2025-64176?
The vulnerability in ThinkDashboard allows an attacker to upload malicious files to the /data directory via the backup import feature, bypassing client-side file-type checks. This can lead to stored XSS attacks and can be exploited for malware distribution or other harmful actions. Users are advised to upgrade to version 0.6.8 to mitigate the risks associated with this vulnerability.
Affected Version(s)
ThinkDashboard < 0.6.8
