Vulnerabilities
Vulnerable Software
Funadmin:  >> Funadmin  Security Vulnerabilities
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
CVSS Score
7.2
EPSS Score
0.006
Published
2024-10-25
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
CVSS Score
7.2
EPSS Score
0.005
Published
2024-10-25
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
CVSS Score
4.9
EPSS Score
0.006
Published
2024-10-25
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
CVSS Score
6.5
EPSS Score
0.005
Published
2024-10-25
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
CVSS Score
7.2
EPSS Score
0.005
Published
2024-10-25
Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
CVSS Score
7.2
EPSS Score
0.005
Published
2024-10-21
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-06-22
A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability.
CVSS Score
3.5
EPSS Score
0.005
Published
2023-05-02
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
CVSS Score
9.8
EPSS Score
0.009
Published
2023-03-10
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-03-08


Contact Us

Shodan ® - All rights reserved