Executive brief
ThinkSNS+ is a Laravel-based social networking platform used to build community sites. This vulnerability allows an unauthenticated remote attacker to escalate privileges and take over user accounts via a flaw in the password reset functionality, potentially giving attackers full control over affected user accounts and the ability to access sensitive data stored in the system.
Technical details
The vulnerability exists in the ResetPasswordController.php component of ThinkSNS+ v.2.4 and allows privilege escalation through the password reset mechanism. The attack is network-reachable and requires no authentication. The root cause appears to be improper validation or expiration handling of verification codes in the password reset flow, enabling account takeover. An attacker can exploit this to reset passwords for arbitrary accounts and gain unauthorized access. Patches or updates should be applied as they become available from the slimkit project.
Affected products
- slimkit plus ThinkSNS+ 2.4
Timeline
- 2026-09-04: disclosed