CVE-2025-14966
- EPSS 0.05%
- Veröffentlicht 19.12.2025 19:32:08
- Zuletzt bearbeitet 24.02.2026 06:16:31
A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file application/common/controller/Backend.php of the component Backend Controller. Executing a manipulation of the argument custom/searchFie...
CVE-2024-7928
- EPSS 92.75%
- Veröffentlicht 19.08.2024 22:15:06
- Zuletzt bearbeitet 13.09.2024 21:33:27
A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. ...
CVE-2024-7453
- EPSS 0.12%
- Veröffentlicht 04.08.2024 05:16:09
- Zuletzt bearbeitet 20.08.2024 15:50:32
A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component Attachment Management Section. T...
- EPSS 0.71%
- Veröffentlicht 13.12.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:42
fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.
CVE-2020-26609
- EPSS 0.26%
- Veröffentlicht 23.02.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:20:09
fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain administrator credentials to log in to the background.
CVE-2020-25967
- EPSS 0.5%
- Veröffentlicht 10.12.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:01
The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.
CVE-2020-21665
- EPSS 0.44%
- Veröffentlicht 17.11.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:46
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
CVE-2019-17431
- EPSS 0.14%
- Veröffentlicht 10.10.2019 12:15:09
- Zuletzt bearbeitet 21.11.2024 04:32:19
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.
CVE-2019-17432
- EPSS 0.12%
- Veröffentlicht 10.10.2019 12:15:09
- Zuletzt bearbeitet 21.11.2024 04:32:19
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.
CVE-2019-11077
- EPSS 0.15%
- Veröffentlicht 11.04.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:29
FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI.