Vulnerabilities (CVE)

Filtered by vendor Funadmin Subscribe
Total 10 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-2477 1 Funadmin 1 Funadmin 2024-05-17 4.0 MEDIUM 6.1 MEDIUM
A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability.
CVE-2023-36097 1 Funadmin 1 Funadmin 2023-06-28 N/A 9.8 CRITICAL
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
CVE-2023-24774 1 Funadmin 1 Funadmin 2023-03-15 N/A 9.8 CRITICAL
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
CVE-2023-24781 1 Funadmin 1 Funadmin 2023-03-14 N/A 9.8 CRITICAL
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
CVE-2023-24780 1 Funadmin 1 Funadmin 2023-03-14 N/A 9.8 CRITICAL
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
CVE-2023-24775 1 Funadmin 1 Funadmin 2023-03-14 N/A 9.8 CRITICAL
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
CVE-2023-24777 1 Funadmin 1 Funadmin 2023-03-14 N/A 9.8 CRITICAL
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
CVE-2023-24782 1 Funadmin 1 Funadmin 2023-03-14 N/A 9.8 CRITICAL
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
CVE-2023-24773 1 Funadmin 1 Funadmin 2023-03-14 N/A 9.8 CRITICAL
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
CVE-2023-24776 1 Funadmin 1 Funadmin 2023-03-14 N/A 9.8 CRITICAL
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.