CVE-2023-24774 | Funadmin 3.2.0 Auth.php selectFields sql injection (Issue 12 / EUVD-2023-1052)
A vulnerability was found in Funadmin 3.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file \controller\auth\Auth.php. The manipulation of the argument selectFields leads to sql injection.
This vulnerability is known as CVE-2023-24774. The attack can only be initiated within the local network. There is no exploit available.