PT-2024-33038 · Funadmin · Funadmin
Lvzcho
·
Published
2024-10-25
·
Updated
2025-06-10
·
CVE-2024-48228
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
funadmin version 5.0.2
Description
An issue was found in the selectfiles method in backendcontrollersysAttachh.php, where it directly stores the passed parameters and values into the
param parameter without filtering, resulting in Cross Site Scripting (XSS).Recommendations
For funadmin version 5.0.2, consider disabling the selectfiles method in backendcontrollersysAttachh.php until a patch is available to prevent Cross Site Scripting (XSS) attacks. Restrict access to the Attachh.php file to minimize the risk of exploitation. Avoid using the
param parameter in the affected method until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Funadmin