Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \app\backend\controller\auth\Auth.php.
References:GSA_kwCzR0hTQS03cHA0LTM4OHgtMnhxas4ABAd_
SQL injection in funadmin
Affected Packages | Affected Versions | Fixed Versions | |
---|---|---|---|
packagist:funadmin/funadmin | <= 5.0.2 | No known fixed version | |
Affected Version RangesAll affected versions1.5.0, 2.1.0, 2.2.6, 2.2.9, 2.2.10, 2.2.11, 2.2.12, 2.2.13, 2.2.14, 2.3.1, 2.4.0, 2.4.1, 2.4.2, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 3.0.1, 3.1.0, 3.1.1, 3.2.0, 3.2.1, 3.2.2, 3.2.3, 3.3.0, 3.3.1, 3.3.2, 3.3.3, 5.0.0, 5.0.1, 5.0.2 |