Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/funadmin/funadmin/issues/29 |
|
History
Mon, 21 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Funadmin
Funadmin funadmin |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:funadmin:funadmin:5.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Funadmin
Funadmin funadmin |
|
| Metrics |
cvssV3_1
|
Mon, 21 Oct 2024 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Funadmin 5.0.2 is vulnerable to SQL Injection.via the selectFields parameter in the index method of \app\backend\controller\auth\Auth.php. | Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. |
Mon, 21 Oct 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Funadmin 5.0.2 is vulnerable to SQL Injection.via the selectFields parameter in the index method of \app\backend\controller\auth\Auth.php. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-21T00:00:00
Updated: 2024-10-21T18:42:42.515Z
Reserved: 2024-10-08T00:00:00
Link: CVE-2024-48231
Updated: 2024-10-21T18:42:32.369Z
Status : Analyzed
Published: 2024-10-21T12:15:08.380
Modified: 2025-06-10T18:57:51.190
Link: CVE-2024-48231
No data.