CVE-2023-24781

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in packagist/funadmin/funadmin

Identifiers

GHSA-vhrv-9f9g-rfrx, CVE-2023-24781

Package Slug

packagist/funadmin/funadmin

Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Description

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.

Affected Versions

All versions up to 3.2.0

Solution

Unfortunately, there is no solution available yet.

Last Modified

2023-03-16

source