ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.Referenceshttps://github.com/thinksaas/ThinkSAAS/issues/18