Unknown · Dcat-Admin · CVE-2024-54775
**Name of the Vulnerable Software and Affected Versions**
Dcat-Admin versions 2.2.0-beta through 2.2.2-beta
**Description**
The issue is a Cross-Site Scripting (XSS) vulnerability. It can be exploited via the "/admin/auth/menu" and "/admin/auth/extensions" API endpoints.
**Recommendations**
For versions 2.2.0-beta through 2.2.2-beta, as a temporary workaround, consider restricting access to the "/admin/auth/menu" and "/admin/auth/extensions" API endpoints until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.