In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the ‘table’ parameter passed is not filtered so a malicious parameter can be passed for SQL injection.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-21667
Reference (s):
- https://github.com/che-my/fastadmin-tp6/issues/2

