An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| funadmin/funadmin(Packagist) | 0 | N/A | N/A |
CVSS Metrics