SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.
https://github.com/liu21st/onethink/issues/39
https://github.com/liu21st/onethink
https://gist.github.com/LioTree/1971a489dd5ff619b89e7a9e1da91152