administrate
Administrate is a library for Rails that generates admin dashboards. These give users clean interfaces that allow them to create, edit, search, and delete records for any model in the application. Administrate aims to provide the best user experience, and doing as much work as possible for you, whilst also being flexible to customise.
Activity
- Latest release
- 10mo ago
- Total releases
- 44
- Cadence
- ~35 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jun 15, 2015
| Version | Released | |
|---|---|---|
1.0.0
major
| ||
1.0.0.beta3
pre
| ||
1.0.0.beta2
pre
| ||
1.0.0.beta1
pre
| ||
0.20.1
patch
|
0.20.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
0.20.0
minor
|
0.20.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
0.19.0
minor
|
0.19.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
0.18.0
minor
|
0.18.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
0.17.0
minor
|
0.17.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.16.0
minor
|
0.16.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.15.0
minor
|
0.15.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.14.0
minor
|
0.14.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.13.0
minor
|
0.13.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.12.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.12.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.11.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.11.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.10.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.10.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.9.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.9.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.8.1
patch
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.8.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.7.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.6.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.6.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.5.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.5.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.4.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.4.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.3.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.3.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.2.2
patch
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.2.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.2.1
patch
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.2.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.2.0
minor
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.2.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.2.0.rc1
pre
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.2.0.rc1
pre
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.1.5
patch
1 CVE
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.1.5
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.1.4
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.1.4
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.1.3
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.1.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.1.2
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.1.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.1
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.1.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.0
minor
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.1.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.0.12
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.0.12
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.0.11
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.0.11
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.0.10
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.0.10
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.0.9
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.8
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.7
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.6
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.4
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.3
patch
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.2
initial
2 CVEs
CVE-2016-3098
GHSA-cc8c-26rj-v2vx
Aug 06, 2022
administrate vulnerable to Cross-Site Request Forgery
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 3 more Show less
0.1.2
0.1.3
0.1.4
Fixed in
0.1.5
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5257
GHSA-2p5p-m353-833w
Mar 13, 2020
Sort order SQL injection in Administrate
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard,
the direction parameter was not validated before being interpolated into the SQL query.
This could present a SQL injection if the attacker were able to modify the Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0. Affected versions
0.0.10
0.0.11
0.0.12
0.0.2
0.0.3
0.0.4
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
+ 19 more Show less
0.1.2
0.1.3
0.1.4
0.1.5
0.10.0
0.11.0
0.12.0
0.2.0
0.2.0.rc1
0.2.1
0.2.2
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
Fixed in
0.13.0
References
Updated Jul 08, 2026 · Source: OSV.dev |