PT-2024-33041 · Funadmin · Funadmin

Lvzcho

·

Published

2024-10-25

·

Updated

2024-10-31

·

CVE-2024-48230

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions funadmin version 5.0.2
Description The issue is related to SQL Injection via the parentField parameter in the index method of backendcontrollerauthAuth.php. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For funadmin version 5.0.2, consider disabling the parentField parameter in the index method of backendcontrollerauthAuth.php as a temporary workaround until a patch is available. Restrict access to the backendcontrollerauthAuth.php module to minimize the risk of exploitation. Avoid using the parentField parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48230
GHSA-2MV8-JJM5-F3HR

Affected Products

Funadmin