CVE-2026-86244
Received Received - Intake

Cross-Site Scripting in FastAdmin User Controller

Vulnerability report for CVE-2026-86244, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: VulDB

Description

A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. Such manipulation of the argument url leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 1.2.1.20210731_beta is able to address this issue. The name of the patch is b3d32e2bf3637488cfe2fc58a27a9d2475b2b51b. It is recommended to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fastadmin fastadmin to 1.2.0.20210401_beta (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86244 is a reflected Cross-Site Scripting (XSS) vulnerability in FastAdmin versions up to 1.2.0.20210401_beta. The issue occurs in the user login and registration modules where the 'url' GET parameter is processed without proper HTML sanitization. Attackers can inject malicious scripts by crafting URLs with payloads like '><img src=x onerror=alert(1)>. When victims visit these URLs, the payload executes in their browsers.

Detection Guidance

To detect this reflected XSS vulnerability in FastAdmin, monitor web server access logs for suspicious URLs containing script payloads like 'url=javascript:' or 'url="><img src=x onerror='. Use tools like Burp Suite or OWASP ZAP to intercept and inspect GET requests to /index/user/register or /index/user/login for unencoded 'url' parameters.

Impact Analysis

This vulnerability allows attackers to execute malicious scripts in victims' browsers when they visit crafted URLs. This can lead to session hijacking, credential theft, or other malicious actions without requiring authentication since login and register pages are publicly accessible.

Compliance Impact

This reflected XSS vulnerability could lead to unauthorized access to user sessions or data, which may violate GDPR's data protection requirements for user consent and security. For HIPAA, it could expose protected health information if exploited in healthcare-related applications using FastAdmin.

Mitigation Strategies

Immediately upgrade FastAdmin to version 1.2.1.20210731_beta or later. Apply the patch commit b3d32e2bf3637488cfe2fc58a27a9d2475b2b51b to template files (dispatch_jump.tpl, login.html, register.html) by adding htmlentities encoding to URL outputs. Validate the 'url' parameter against an allowlist in the controller.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86244. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart