ZeroHour

CVE-2024-48228

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p20
Published
()
Modified
Description

An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).

Vendors
funadmin
Products
funadmin
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.