Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1052 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. |
Github GHSA |
GHSA-jx2x-fg9p-7gc7 | Funadmin vulnerable to SQL injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/funadmin/funadmin/issues/12 |
|
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-28T15:25:51.275Z
Reserved: 2023-01-30T00:00:00.000Z
Link: CVE-2023-24774
Updated: 2024-08-02T11:03:19.156Z
Status : Modified
Published: 2023-03-10T13:15:11.033
Modified: 2025-02-28T16:15:36.360
Link: CVE-2023-24774
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA