CVE-2019-17432

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
10/10/2019
Last modified:
24/08/2020

Description

An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fastadmin:fastadmin:1.0.0.20190705:beta:*:*:*:*:*:*


References to Advisories, Solutions, and Tools