CVE-2023-24775

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in packagist/funadmin/funadmin

Identifiers

GHSA-v43v-pv95-jc55, CVE-2023-24775

Package Slug

packagist/funadmin/funadmin

Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Description

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.

Affected Versions

All versions up to 3.2.0

Solution

Unfortunately, there is no solution available yet.

Last Modified

2023-03-16

source