Caipeichao ThinkOX Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Caipeichao ThinkOX version 1.0. The issue arises in the search component, specifically within the file '/ThinkOX-master/index.php?s=/Weibo/Index/search.html'. The vulnerability is triggered by manipulating the 'keywords' argument, allowing for remote exploitation that requires user interaction.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, navigate to the ThinkOX 1.0 homepage and use the search box. Enter a payload that exploits the cross-site scripting vulnerability by injecting script elements or other HTML that can be executed. The injected script will run in the context of the user’s session.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.