Vulnerabilities > Filerun

DATE CVE VULNERABILITY TITLE RISK
2023-12-22 CVE-2022-47532 SQL Injection vulnerability in Filerun 20220519
FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.
network
low complexity
filerun CWE-89
critical
9.8
2017-09-30 CVE-2017-14738 SQL Injection vulnerability in Filerun 2017.09.18
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
network
low complexity
filerun CWE-89
critical
9.8