Karson

2 exploits Active since Apr 2018
CVE-2018-10268 GITEE MEDIUM php
FastAdmin V1.0.0.20180417_beta - XSS
An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter.
6,913 stars
CVSS 5.4
CVE-2020-21665 WRITEUP HIGH WRITEUP
Fastadmin - SQL Injection
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
CVSS 7.2