CVE-2024-7928 is a path traversal vulnerability in FastAdmin versions up to and including 1.3.3.20220121. The vulnerability exists in the /index/ajax/lang endpoint, where the 'lang' parameter is insufficiently sanitized, allowing remote attackers to manipulate it and access arbitrary files on the server. This can be exploited without authentication, enabling attackers to retrieve sensitive files such as database configuration files. The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Python proof-of-concept (POC) exploit for CVE-2024-7928, a vulnerability in FastAdmin. The main file, CVE-2024-7928.py, is a command-line tool that targets FastAdmin instances over HTTP(S). It attempts to exploit a path traversal vulnerability by sending a GET request to the endpoint /index/ajax/lang?lang=../../application/database. If the target is vulnerable, the response contains database credentials in a JSONP format, which the script parses and displays (type, hostname, database, username, password, hostport). The script supports both single-target and bulk-target modes, logs results to logs/scan.log, and uses multithreading for bulk scans. The repository also includes a README.md with usage instructions and references, and a requirements.txt listing Python dependencies (requests, urllib3). The exploit is a POC and does not provide post-exploitation capabilities beyond information disclosure.
This repository provides a Python proof-of-concept exploit for CVE-2024-7928, a directory traversal vulnerability in FastAdmin (up to version 1.3.3.20220121). The main script, CVE-2024-7928.py, allows users to scan single or multiple FastAdmin instances for the vulnerability. If a target is vulnerable, the script exploits the /index/ajax/lang endpoint with a crafted lang parameter to traverse directories and access the application's database configuration file. The script then parses and displays sensitive database details (type, hostname, database, username, password, hostport) from the server's response. The repository also includes a README.md with usage instructions and references, and a requirements.txt listing the necessary Python dependencies. The exploit is network-based, requires no authentication, and is designed for information disclosure. No fake or destructive functionality is present; the code is a legitimate exploit POC.
This repository provides an operational exploit for CVE-2024-7928, an arbitrary file read vulnerability in FastAdmin versions prior to V1.3.4.20220530. The main script, cvehunter.py, is a Python tool that can scan single or multiple FastAdmin instances for the vulnerability. It does so by sending a crafted GET request to the endpoint /index/ajax/lang with a path traversal payload (lang=../../application/database), which, if successful, returns the contents of the application's database configuration file. The tool parses the JSONP response to extract and display sensitive database connection details, including type, hostname, port, database name, username, and password. The script supports asynchronous scanning, proxy usage, output to file, and verbose output. The repository also includes a requirements.txt for dependencies and a README.md with usage instructions. No hardcoded IPs or domains are present; the tool is designed to be used against user-supplied targets. The exploit is operational, providing real credential extraction if the target is vulnerable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.