Cross Site Scripting Vulnerability in FastAdmin User Controller
CVE-2026-86244
Key Information:
Badges
What is CVE-2026-86244?
A security vulnerability exists in the FastAdmin User Controller, specifically in the register/login functionality within the User.php file. This flaw permits attackers to manipulate the URL argument, which can lead to cross site scripting (XSS). The vulnerability is remotely exploitable and poses a significant risk if left unaddressed. It is crucial to update to version 1.2.1.20210731_beta, which includes a patch identified by the commit b3d32e2bf3637488cfe2fc58a27a9d2475b2b51b, to mitigate the risks associated with this vulnerability.
Affected Version(s)
FastAdmin 1.2.0.20210401_beta
FastAdmin 1.2.1.20210731_beta
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
