Cross-Site Scripting in FastAdmin Product by FastAdmin
CVE-2018-10268

5.4MEDIUM

Key Information:

Vendor

Fastadmin

Status
Vendor
CVE Published:
22 April 2018

What is CVE-2018-10268?

A Cross-Site Scripting (XSS) vulnerability has been identified within FastAdmin version V1.0.0.20180417_beta. The issue arises when user input is not adequately sanitized, particularly through the avatar parameter in the User controller of the application API. An attacker could exploit this vulnerability to inject malicious scripts, potentially compromising the security of user sessions and leading to unauthorized access or data theft. Implementing input validation and output encoding can help mitigate this risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.