Vulnerabilities
Vulnerable Software
Funadmin:  >> Funadmin  >> 3.2.0  Security Vulnerabilities
A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability.
CVSS Score
3.5
EPSS Score
0.001
Published
2023-05-02
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
CVSS Score
9.8
EPSS Score
0.006
Published
2023-03-10
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-03-08
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-03-08
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-03-08
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
CVSS Score
9.8
EPSS Score
0.002
Published
2023-03-08
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
CVSS Score
9.8
EPSS Score
0.583
Published
2023-03-07
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-03-07
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.
CVSS Score
9.8
EPSS Score
0.014
Published
2023-03-06


Contact Us

Shodan ® - All rights reserved