SQL Injection Vulnerability in Funadmin by Funadmin
CVE-2023-24773
9.8CRITICAL
What is CVE-2023-24773?
Funadmin v3.2.0 is vulnerable to a SQL injection attack via the id parameter at /databases/database/list endpoint. This flaw could enable malicious actors to manipulate database queries, potentially leading to unauthorized access to sensitive information or database compromise. Immediate assessment of security measures and implementation of patches is recommended to mitigate risks.
