SQL Injection Vulnerability in FastAdmin by FastAdmin Team
CVE-2020-21665

7.2HIGH

Key Information:

Vendor

Fastadmin

Status
Vendor
CVE Published:
17 November 2020

What is CVE-2020-21665?

FastAdmin version 1.0.0.20191212_beta contains a vulnerability where users with administrator privileges can be exploited through SQL injection. This occurs via specially crafted parameters in the URL, specifically at the endpoint /admin/ajax/weigh. Such an exploit could allow an attacker to manipulate database queries, potentially compromising sensitive data and altering the behavior of the application. Proper input validation and sanitation measures should be considered to mitigate this risk.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.