Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2023-2477
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-24774
Disclosure Date: March 10, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
0
Attacker Value
Unknown
CVE-2023-24777
Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
0
Attacker Value
Unknown
CVE-2023-24782
Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
0
Attacker Value
Unknown
CVE-2023-24773
Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
0
Attacker Value
Unknown
CVE-2023-24780
Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
0
Attacker Value
Unknown
CVE-2023-24775
Disclosure Date: March 07, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
0
Attacker Value
Unknown
CVE-2023-24781
Disclosure Date: March 07, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
0
Attacker Value
Unknown
CVE-2023-24776
Disclosure Date: March 06, 2023 (last updated October 08, 2023)
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.
0