PT-2024-5821 · Fastadmin · Fastadmin
Rabbit
+1
·
Published
2024-08-19
·
Updated
2026-02-13
·
CVE-2024-7928
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FastAdmin versions prior to 1.3.4.20220530
Description
A problematic issue exists in FastAdmin related to improper path restriction within the
/index/ajax/lang component. This allows for path traversal, potentially enabling remote attackers to access sensitive information. The issue affects an unknown functionality within the /index/ajax/lang file, where manipulation of the lang parameter can lead to unauthorized data access. Reports indicate that approximately 14,000 instances may be affected yearly. Exploitation of this issue has been publicly disclosed and is being actively used to retrieve database details. The API endpoint /index/ajax/lang is involved, and the lang parameter is a vulnerable parameter.Recommendations
Upgrade to FastAdmin version 1.3.4.20220530 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastadmin