Impact
A flaw in the database.php component of FastAdmin allows a remote attacker to manipulate an unknown function and execute actions with privileges that are not required for normal operation. The impact is a privilege escalation that could compromise the integrity and confidentiality of the database and any data stored therein. The weakness is classified as Privilege Escalation (CWE-250).
Affected Systems
FastAdmin versions 1.6.1.20250430 and 1.6.5.20260602 are affected. The vulnerability resides in the Database Management module and may affect any installation using these releases.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the EPSS score is not available, meaning publicly shared exploitation data is limited. The exploit is publicly documented and can be launched remotely. Because no official patch or workaround is listed, the risk remains high for any deployed instance without mitigation. The vulnerability’s nature suggests that an attacker could use the unnecessary privileges to alter or delete database content, elevate internal accounts, or compromise other system components that rely on the database. Given that the vulnerability appears in a core module, the likelihood of exploitation is significant when exposed to the internet.
OpenCVE Enrichment