FunAdmin是FunAdmin开源的一个基于 ThinkPHP6+Layui 开发的轻量级高颜值后台开发系统。 FunAdmin 7.1.0-rc4及之前版本存在代码问题漏洞,该漏洞源于对组件Backend Endpoint的文件app/common/service/AuthCloudService.php中函数getMember的参数cloud_account的错误操作,可能导致反序列化。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | funadmin | 7.1.0-rc1 |
cpe:2.3:a:funadmin:funadmin:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/aykhan32/CVE-2026-2898-FunAdmin-Deserialization | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-2952 | 7.3 HIGH | Vaelsys HTTP POST Request tree_server.php os command injection |
| CVE-2026-2945 | 6.3 MEDIUM | JeecgBoot uploadImgByHttp server-side request forgery |
| CVE-2026-2913 | 2.5 LOW | libvips source.c vips_source_read_to_memory heap-based overflow |
| CVE-2026-2897 | 2.4 LOW | funadmin Backend index.html cross site scripting |
No comments yet