CVE-2024-7928

MEDIUM EXPLOITED NUCLEI

fastadmin < 1.3.4.20220530 - Path Traversal via /index/ajax/lang lang Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-7928 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including bigb0x, gh-ost00, th3gokul. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits a directory traversal vulnerability in FastAdmin to retrieve database configuration details. It sends a crafted request to expose sensitive information such as database credentials.

Description

A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.4.20220530 is able to address this issue. It is recommended to upgrade the affected component.

Exploits (7)

nomisec WORKING POC 69 stars
by bigb0x · remote
https://github.com/bigb0x/CVE-2024-7928

This PoC exploits a directory traversal vulnerability in FastAdmin to retrieve database configuration details. It sends a crafted request to expose sensitive information such as database credentials.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FastAdmin up to 1.3.3.20220121
No auth needed
Prerequisites: Network access to the target FastAdmin instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 9 stars
by gh-ost00 · infoleak
https://github.com/gh-ost00/CVE-2024-7928

This PoC exploits CVE-2024-7928 to retrieve database configuration details from vulnerable FastAdmin instances via a path traversal vulnerability. It sends a crafted request to expose sensitive database credentials and connection details.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FastAdmin (version not specified)
No auth needed
Prerequisites: Network access to the target FastAdmin instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by th3gokul · infoleak
https://github.com/th3gokul/CVE-2024-7928

This repository contains a Python-based exploit tool for CVE-2024-7928, an arbitrary file reading vulnerability in FastAdmin versions prior to V1.3.4.20220530. The tool detects and exploits the vulnerability to retrieve database configuration details by leveraging a path traversal flaw in the language file endpoint.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FastAdmin < V1.3.4.20220530
No auth needed
Prerequisites: Network access to the target FastAdmin instance · Exposed /index/ajax/lang endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by diamorphine666 · poc
https://github.com/diamorphine666/CVE-2024-7928

This repository contains a functional exploit for CVE-2024-7928, a path traversal vulnerability in FastAdmin. The exploit sends a crafted request to '/index/ajax/lang' with a traversal payload to leak database credentials from the application's configuration file.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FastAdmin up to 1.3.3.20220121
No auth needed
Prerequisites: target URL or list of URLs
devstral-2 · analyzed May 24, 2026 Full analysis →
nomisec WORKING POC
by w666-glitch · poc
https://github.com/w666-glitch/CVE-2024-7928

This repository contains a functional exploit for CVE-2024-7928, a path traversal vulnerability in FastAdmin up to version 1.3.3.20220121. The exploit leverages the vulnerable endpoint `/index/ajax/lang` to traverse directories and leak database credentials from the application's configuration file.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FastAdmin up to 1.3.3.20220121
No auth needed
Prerequisites: Target running vulnerable FastAdmin version · Network access to the target
devstral-2 · analyzed Apr 22, 2026 Full analysis →
nomisec WORKING POC
by wh6amiGit · remote
https://github.com/wh6amiGit/CVE-2024-7928

This exploit targets a path traversal vulnerability in FastAdmin up to version 1.3.3.20220121, allowing remote attackers to read sensitive database configuration files via the `/index/ajax/lang` endpoint. The script uses asynchronous HTTP requests to check for vulnerability and extract database credentials.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FastAdmin up to 1.3.3.20220121
No auth needed
Prerequisites: Network access to the target FastAdmin instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/fa-rrel/cve-2024-7928

This repository contains a functional exploit PoC for CVE-2024-7928, which targets FastAdmin instances to retrieve database details via an unauthenticated path traversal vulnerability. The script sends a crafted request to expose sensitive database configuration information.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FastAdmin
No auth needed
Prerequisites: Target URL or list of URLs
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Nuclei Templates (1)

FastAdmin < V1.3.4.20220530 - Path Traversal
MEDIUMby s4e-io,Hel10-Web
FOFA: icon_hash="-1036943727"

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.275114
Permissions Required, Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.275114
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.392202

Scores

CVSS v3 4.3
EPSS 0.9180
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2024-08-29
CWE
CWE-22
Status published
Products (1)
fastadmin/fastadmin < 1.3.4.20220530
Published Aug 19, 2024
Tracked Since Feb 18, 2026