Releases0
Stars20
fastadmin升级thinkphp6.0

CVE History

CVEPublishedCVSS v3CVSS v2
7.2 HIGH6.5 MEDIUM

In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can be passed for SQL injection.