SQL Injection Vulnerability in FastAdmin by FastAdmin Team
CVE-2020-21665
7.2HIGH
What is CVE-2020-21665?
FastAdmin version 1.0.0.20191212_beta contains a vulnerability where users with administrator privileges can be exploited through SQL injection. This occurs via specially crafted parameters in the URL, specifically at the endpoint /admin/ajax/weigh. Such an exploit could allow an attacker to manipulate database queries, potentially compromising sensitive data and altering the behavior of the application. Proper input validation and sanitation measures should be considered to mitigate this risk.
