Vulnerabilities
Vulnerable Software
Funadmin:  >> Funadmin  Security Vulnerabilities
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
CVSS Score
7.2
EPSS Score
0.002
Published
2024-10-25
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
CVSS Score
7.2
EPSS Score
0.002
Published
2024-10-25
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
CVSS Score
4.9
EPSS Score
0.002
Published
2024-10-25
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-10-25
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
CVSS Score
7.2
EPSS Score
0.001
Published
2024-10-25
Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
CVSS Score
7.2
EPSS Score
0.001
Published
2024-10-21
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
CVSS Score
9.8
EPSS Score
0.004
Published
2023-06-22
A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability.
CVSS Score
3.5
EPSS Score
0.001
Published
2023-05-02
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
CVSS Score
9.8
EPSS Score
0.014
Published
2023-03-10
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
CVSS Score
9.8
EPSS Score
0.002
Published
2023-03-08


Contact Us

Shodan ® - All rights reserved