PT-2020-15380 · Fastadmin · Fastadmin-Tp6

0Xzmzo

·

Published

2020-11-13

·

Updated

2020-12-01

·

CVE-2020-21667

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions fastadmin-tp6 version 1.0
Description The issue concerns a lack of filtering for the table parameter in the app/admin/controller/Ajax.php file, allowing a malicious parameter to be passed for SQL injection.
Recommendations For fastadmin-tp6 version 1.0, consider filtering or validating the table parameter to prevent malicious input and SQL injection attacks. As a temporary workaround, restrict access to the Ajax.php file or the table parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-21667

Affected Products

Fastadmin-Tp6