Unknown · Fastapi-Admin Pro · CVE-2024-42818
**Name of the Vulnerable Software and Affected Versions**
fastapi-admin pro version 0.1.4
**Description**
A cross-site scripting (XSS) vulnerability in the Config-Create function allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the `Product Name` parameter.
**Recommendations**
For fastapi-admin pro version 0.1.4, upgrade to version 0.1.5 to remediate this issue. As a temporary workaround, consider restricting the use of the Config-Create function until the issue is resolved. Avoid using the `Product Name` parameter in the affected function to minimize the risk of exploitation.