SQL Injection Vulnerability in Funadmin v3.2.0 by Funadmin
CVE-2023-24774
9.8CRITICAL
What is CVE-2023-24774?
Funadmin v3.2.0 is susceptible to a SQL injection vulnerability through the selectFields parameter in the Auth.php controller. This flaw can allow attackers to manipulate database queries, leading to unauthorized access and potential data breaches. Developers are encouraged to implement input validation and prepared statements to mitigate this risk.
