CVE-2017-14738 describes a critical remote SQL injection vulnerability in FileRun versions 2017.09.18 and below, stemming from insufficient input sanitization in the 'metafield' parameter within the 'metasearch' module. With a CVSS score of 9.8, this vulnerability allows an unauthenticated attacker to execute arbitrary SQL commands, potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog or showing significant community discussion, public exploit code (EDB-42922) is available, indicating a clear path for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2017.09.18CPE matchmatch criteria | cpe:2.3:a:filerun:filerun:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.