Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FunAdmin 安全漏洞
Vulnerability Description
FunAdmin是FunAdmin开源的一个基于 ThinkPHP6+Layui 开发的轻量级高颜值后台开发系统。 FunAdmin 5.0.2版本存在安全漏洞,该漏洞源于ackendcontrollersysAttachh.php中的selectfiles方法不经过过滤就直接将传入的参数及值存入param参数中,从而导致跨站脚本攻击(XSS)。
CVSS Information
N/A
Vulnerability Type
N/A