All versions of Funadmin are discovered to contain a Remote Code Execution (RCE) vulnerability via the component "\controller\Addon.php".