Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown
CVE-2024-8155
Disclosure Date: August 25, 2024 (last updated February 26, 2025)
A vulnerability classified as critical was found in ContiNew Admin 3.2.0. Affected by this vulnerability is the function top.continew.starter.extension.crud.controller.BaseController#tree of the file /api/system/dept/tree?sort=parentId%2Casc&sort=sort%2Casc. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-8150
Disclosure Date: August 25, 2024 (last updated February 26, 2025)
A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-24774
Disclosure Date: March 10, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
0
Attacker Value
Unknown
CVE-2023-24777
Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
0
Attacker Value
Unknown
CVE-2023-24782
Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
0
Attacker Value
Unknown
CVE-2023-24773
Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
0
Attacker Value
Unknown
CVE-2023-24780
Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
0
Attacker Value
Unknown
CVE-2023-24775
Disclosure Date: March 07, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
0
Attacker Value
Unknown
CVE-2023-24781
Disclosure Date: March 07, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
0
Attacker Value
Unknown
CVE-2023-24776
Disclosure Date: March 06, 2023 (last updated March 07, 2025)
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.
0