← back
CVE-2024-7928mediumobserved exploitationCWE-22

FastAdmin lang path traversal

75Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 5.3epss 17%
from disclosure to weapon1 days
Published on NVDAug 19
1st PoC+1d
VulnCheck+10d
exploitation probability
17%top 3% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.4.20220530 is able to address this issue. It is recommended to upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
n/a · FastAdmin
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.