-
CVSS Score
-The vulnerability report explicitly states the list method in table.php handles the 'id' parameter without proper sanitization. The reproduction POC shows SQL injection via crafted 'id' parameter in the URL, and the issue description confirms direct SQL concatenation occurs in this endpoint. The file path and method name are specifically mentioned in both the CVE description and GitHub issue #5.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| funadmin/funadmin | composer | <= 3.2.0 |