SQL Injection Vulnerability in Funadmin 5.0.2 by Funadmin
CVE-2024-48230
7.2HIGH
What is CVE-2024-48230?
The SQL injection vulnerability in Funadmin version 5.0.2 allows attackers to exploit the application by manipulating the parentField parameter in the index method of the Auth controller located in the backend directory. This flaw can lead to unauthorized access to sensitive data, modification of database entries, and potentially complete control over the database, which poses a significant risk to users and their information. Proper validation and sanitization measures should be implemented to mitigate this vulnerability.
