[go: up one dir, main page]
More Web Proxy on the site http://driver.im/

FastAdmin 1.5.0.20240328 Attachment Management Section 4?dialog=1 row[url]/row[imagewidth]/row[imageheight] cross site scripting

I FastAdmin 1.5.0.20240328 var ett problematisksvag punkt identifieras. Som påverkar en okänd funktion filen /[admins_url].php/general/attachment/edit/ids/4?dialog=1 av komponenten Attachment Management Section. Manipulering av argumenten row[url]/row[imagewidth]/row[imageheight] en okänd ingång leder till en sårbarhet klass cross site scripting svag punkt. Den rådgivande finns tillgänglig för nedladdning på github.com. Denna svaga punkt behandlas som CVE-2024-7453. Attacken på nätet kan. Det finns tekniska detaljer känd. Han deklarerade proof-of-concept. Den exploit kan laddas ner från github.com.

4 Ändringar · 87 Datapunkter

FältSkapad
03/08/2024 09:02
Update 1/3
03/08/2024 15:21
Update 2/3
04/08/2024 09:25
Update 3/3
21/08/2024 01:08
software_nameFastAdminFastAdminFastAdminFastAdmin
software_version1.5.0.202403281.5.0.202403281.5.0.202403281.5.0.20240328
software_componentAttachment Management SectionAttachment Management SectionAttachment Management SectionAttachment Management Section
software_file/swdHGFizaW.php/general/attachment/edit/ids/4?dialog=1/[admins_url].php/general/attachment/edit/ids/4?dialog=1/[admins_url].php/general/attachment/edit/ids/4?dialog=1/[admins_url].php/general/attachment/edit/ids/4?dialog=1
software_argumentrow[url]/row[imagewidth]/row[imageheight]row[url]/row[imagewidth]/row[imageheight]row[url]/row[imagewidth]/row[imageheight]row[url]/row[imagewidth]/row[imageheight]
vulnerability_cweCWE-79 (cross site scripting)CWE-79 (cross site scripting)CWE-79 (cross site scripting)CWE-79 (cross site scripting)
vulnerability_risk1111
cvss3_vuldb_avNNNN
cvss3_vuldb_acLLLL
cvss3_vuldb_prHHHH
cvss3_vuldb_uiRRRR
cvss3_vuldb_sUUUU
cvss3_vuldb_cNNNN
cvss3_vuldb_iLLLL
cvss3_vuldb_aNNNN
cvss3_vuldb_ePPPP
cvss3_vuldb_rcCCCC
advisory_urlhttps://github.com/Hebing123/cve/issues/65https://github.com/Hebing123/cve/issues/65https://github.com/Hebing123/cve/issues/65https://github.com/Hebing123/cve/issues/65
advisory_confirm_urlhttps://github.com/Hebing123/cve/issues/66https://github.com/Hebing123/cve/issues/66https://github.com/Hebing123/cve/issues/66https://github.com/Hebing123/cve/issues/66
exploit_availability1111
exploit_publicity1111
exploit_urlhttps://github.com/Hebing123/cve/issues/65https://github.com/Hebing123/cve/issues/65https://github.com/Hebing123/cve/issues/65https://github.com/Hebing123/cve/issues/65
source_cveCVE-2024-7453CVE-2024-7453CVE-2024-7453CVE-2024-7453
cna_responsibleVulDBVulDBVulDBVulDB
cvss2_vuldb_avNNNN
cvss2_vuldb_acLLLL
cvss2_vuldb_auMMMM
cvss2_vuldb_ciNNNN
cvss2_vuldb_iiPPPP
cvss2_vuldb_aiNNNN
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcCCCC
cvss4_vuldb_avNNNN
cvss4_vuldb_acLLLL
cvss4_vuldb_prHHHH
cvss4_vuldb_vcNNNN
cvss4_vuldb_viLLLL
cvss4_vuldb_vaNNNN
cvss4_vuldb_ePPPP
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_uiNNNN
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore3.33.33.33.3
cvss2_vuldb_tempscore3.03.03.03.0
cvss3_vuldb_basescore2.42.42.42.4
cvss3_vuldb_tempscore2.32.32.32.3
cvss3_meta_basescore2.42.42.43.2
cvss3_meta_tempscore2.32.32.33.2
cvss4_vuldb_bscore5.15.15.15.1
cvss4_vuldb_btscore2.02.02.02.0
advisory_date1722636000 (03/08/2024)1722636000 (03/08/2024)1722636000 (03/08/2024)1722636000 (03/08/2024)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
cve_nvd_summaryA vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component Attachment Management Section. The manipulation of the argument row[url]/row[imagewidth]/row[imageheight] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273544.A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component Attachment Management Section. The manipulation of the argument row[url]/row[imagewidth]/row[imageheight] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273544.
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prHH
cvss3_cna_uiRR
cvss3_cna_sUU
cvss3_cna_cNN
cvss3_cna_iLL
cvss3_cna_aNN
cvss3_cna_basescore2.42.4
cvss2_cna_avNN
cvss2_cna_acLL
cvss2_cna_auMM
cvss2_cna_ciNN
cvss2_cna_iiPP
cvss2_cna_aiNN
cvss2_cna_basescore3.33.3
cve_nvd_summaryesSe encontró una vulnerabilidad en FastAdmin 1.5.0.20240328. Ha sido declarada problemática. Esta vulnerabilidad afecta a código desconocido del archivo /[admins_url].php/general/attachment/edit/ids/4?dialog=1 del componente sección de gestión de archivos adjuntos. La manipulación del argumento fila[url]/fila[ancho de imagen]/fila[alto de imagen] conduce a cross site scripting. El ataque se puede iniciar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. El identificador de esta vulnerabilidad es VDB-273544.
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prH
cvss3_nvd_uiR
cvss3_nvd_sC
cvss3_nvd_cL
cvss3_nvd_iL
cvss3_nvd_aN
cvss3_nvd_basescore4.8

Interested in the pricing of exploits?

See the underground prices here!