An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS03cHA0LTM4OHgtMnhxas4ABAd_

High CVSS: 8.6 EPSS: 0.00132% (0.33692 Percentile) EPSS:

SQL injection in funadmin

Affected Packages Affected Versions Fixed Versions
packagist:funadmin/funadmin <= 5.0.2 No known fixed version
0 Dependent packages
0 Dependent repositories
853 Downloads total

Affected Version Ranges

All affected versions

1.5.0, 2.1.0, 2.2.6, 2.2.9, 2.2.10, 2.2.11, 2.2.12, 2.2.13, 2.2.14, 2.3.1, 2.4.0, 2.4.1, 2.4.2, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 3.0.1, 3.1.0, 3.1.1, 3.2.0, 3.2.1, 3.2.2, 3.2.3, 3.3.0, 3.3.1, 3.3.2, 3.3.3, 5.0.0, 5.0.1, 5.0.2

Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \app\backend\controller\auth\Auth.php.

References: