XSS Vulnerability in FastAdmin by Karson Zhang
CVE-2020-26609

5.4MEDIUM

Key Information:

Vendor

Fastadmin

Status
Vendor
CVE Published:
23 February 2021

What is CVE-2020-26609?

FastAdmin version 1.0.0.20200506_beta is susceptible to a cross-site scripting (XSS) vulnerability, which can be exploited by attackers to inject malicious scripts into web pages viewed by administrators. Successful exploitation of this vulnerability may allow attackers to steal administrator credentials and gain unauthorized access to administrative functions. It's crucial for users of this version to apply security patches and updates to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.