Description
A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file application/common/controller/Backend.php of the component Backend Controller. Executing manipulation of the argument custom/searchField can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Timeline
| 2025-12-19: | Advisory disclosed |
| 2025-12-19: | VulDB entry created |
| 2025-12-19: | VulDB entry last update |
Credits
pemic (VulDB User)
References
vuldb.com/?id.337601 (VDB-337601 | FastAdmin Backend Controller Backend.php selectpage sql injection)
vuldb.com/?ctiid.337601 (VDB-337601 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.718309 (Submit #718309 | FastAdmin 1.7.0.20250506 SQL Injection)
vuldb.com/?submit.718339 (Submit #718339 | FastAdmin 1.7.0.20250506 SQL Injection (Duplicate))
note-hxlab.wetolink.com/share/1924AEdgGFYu
note-hxlab.wetolink.com/share/auEz57nwynMq
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.