PT-2024-30176 · Unknown · Fastapi-Admin Pro
Aprilliar13
·
Published
2024-08-26
·
Updated
2024-08-30
·
CVE-2024-42818
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
fastapi-admin pro version 0.1.4
Description
A cross-site scripting (XSS) vulnerability in the Config-Create function allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the
Product Name parameter.Recommendations
For fastapi-admin pro version 0.1.4, upgrade to version 0.1.5 to remediate this issue. As a temporary workaround, consider restricting the use of the Config-Create function until the issue is resolved. Avoid using the
Product Name parameter in the affected function to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastapi-Admin Pro