Executive brief
Milk admin, an open-source PHP dashboard and CRUD generator, contains a security flaw that allows attackers to inject malicious scripts into the application. By tricking a logged-in administrator into clicking a specially crafted link, an attacker could potentially steal session cookies, hijack administrative accounts, or perform unauthorized actions on the dashboard. This vulnerability affects the documentation module of the software.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Milk admin versions 0.9.8 and earlier. The flaw is located in the 'action' parameter within 'Modules/Docs/DocsController.php'. The application fails to properly sanitize or encode user-supplied input before rendering it in the web interface. A remote attacker can exploit this by sending a crafted URL to a victim, leading to the execution of arbitrary JavaScript or HTML in the context of the victim's browser session. As of the advisory date, no official patch has been released; users are advised to implement Web Application Firewall (WAF) rules or restrict access to the affected module.
Affected products
- giuliopanda Milk admin <=0.9.8
Timeline
- 2026-07-27: advisory: NVD publication date
- 2026-07-27: disclosed: Public disclosure by researcher via GitHub advisory