Afian
Afian Filerun: vulnerabilities and CVEs
Afian Filerun has 14 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs14
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28876 | Medium (4.3) | 0.48% | — | Dec 6, 2023 | A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on files uploaded by other users. |
| CVE-2023-28875 | Medium (5.4) | 0.43% | — | Dec 6, 2023 | A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link. |
| CVE-2022-30469 | High (8.8) | 1.4% | — | Jun 6, 2022 | In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman§ion=get&page=grid` leads to SQL injection. |
| CVE-2022-30470 | Critical (9.8) | 2.6% | — | Jun 2, 2022 | In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user. |
| CVE-2021-35506 | Medium (6.1) | 0.74% | — | Oct 5, 2021 | Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action. |
| CVE-2021-35505 | High (7.2) | 2.8% | — | Oct 5, 2021 | Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary. |
| CVE-2021-35504 | High (7.2) | 3.2% | — | Oct 5, 2021 | Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary. |
| CVE-2021-35503 | Medium (6.1) | 0.74% | — | Oct 5, 2021 | Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs. |
| CVE-2019-12905 | Medium (6.1) | 3.6% | — | Jun 20, 2019 | FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed in FileRun 2019.06.01. |
| CVE-2019-12459 | Medium (5.3) | 1.8% | — | May 30, 2019 | FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01. |
| CVE-2019-12458 | Medium (5.3) | 1.8% | — | May 30, 2019 | FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01. |
| CVE-2019-12457 | Medium (5.3) | 1.8% | — | May 30, 2019 | FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01. |
| CVE-2018-7735 | High (7.2) | 1.3% | — | Mar 6, 2018 | Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata§ion=cpanel&page=list_filetypes request. |
| CVE-2018-7734 | High (7.2) | 1.3% | — | Mar 6, 2018 | Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users§ion=cpanel&page=list request. |