Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2024-8155

Disclosure Date: August 25, 2024 (last updated February 26, 2025)
A vulnerability classified as critical was found in ContiNew Admin 3.2.0. Affected by this vulnerability is the function top.continew.starter.extension.crud.controller.BaseController#tree of the file /api/system/dept/tree?sort=parentId%2Casc&sort=sort%2Casc. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-8150

Disclosure Date: August 25, 2024 (last updated February 26, 2025)
A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-24774

Disclosure Date: March 10, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
Attacker Value
Unknown

CVE-2023-24777

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
Attacker Value
Unknown

CVE-2023-24782

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
Attacker Value
Unknown

CVE-2023-24773

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
Attacker Value
Unknown

CVE-2023-24780

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
Attacker Value
Unknown

CVE-2023-24775

Disclosure Date: March 07, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
Attacker Value
Unknown

CVE-2023-24781

Disclosure Date: March 07, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
Attacker Value
Unknown

CVE-2023-24776

Disclosure Date: March 06, 2023 (last updated March 07, 2025)
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.