SQL Injection Vulnerability in Funadmin 5.0.2 by Funadmin
CVE-2024-48231
7.2HIGH
What is CVE-2024-48231?
The Funadmin version 5.0.2 contains a SQL Injection vulnerability that can be exploited through the selectFields parameter in the index method located in the backend/controller/auth/Auth.php file. This flaw potentially allows attackers to manipulate SQL queries, leading to unauthorized access to sensitive data. Organizations using this version should consider upgrading or applying patches to mitigate the risks associated with this vulnerability.
