SQL Injection Vulnerability in Funadmin Version 3.2.0 by Funadmin
CVE-2023-24781
9.8CRITICAL
What is CVE-2023-24781?
Funadmin version 3.2.0 is susceptible to a SQL injection vulnerability through the 'selectFields' parameter located in the member level management script. This flaw may allow unauthorized users to manipulate database queries, potentially gaining access to sensitive information or altering database content. It's critical for users to apply security best practices and ensure timely updates to mitigate risks associated with this vulnerability.
