← Back

CVE-2024-48228

nvd nist
Published: Oct 25, 2024Modified: Jun 10, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).

Affected (1)

Products: Funadmin: Funadmin
1 product
Funadmin
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0.2

References (1)

Source: cve@mitre.org
ExploitIssue Tracking

Timeline

No history available yet.