fastadminnet/fastadmin

fastadminnet/fastadmin

Releases62
Frequency1 month 3 weeks
Last Release
Stars1.9K
基于 ThinkPHP 和 Bootstrap 的极速后台开发框架,一键生成 CRUD,自动生成控制器、模型、视图、JS、语言包、菜单、回收站。

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM3.5 LOW

fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain administrator credentials to log in to the background.

7.2 HIGH6.5 MEDIUM

In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.