Filerun

Vendor:

First CVE: Mar 6, 2018 · Active for 8 years

14
Total CVEs
More Total CVEs than 92% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Filerun over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2018
8 years ago
Most Recent CVE
Dec 6, 2023
964 days ago

CVE Severity & Scoring

Filerun14 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (71.4%)
Unknown0 (0.0%)
Required4 (28.6%)
Privileges Required
Low3 (21.4%)
High4 (28.6%)
None7 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI. This issue has been fixed in FileRun 2019.06.01.
Jun 20, 20196.132NOYES
In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver u
Jun 2, 20229.830NONO
In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.
Jun 6, 20228.828NONO
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.
Oct 5, 20217.226NONO
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.
Oct 5, 20217.226NONO
Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.
Oct 5, 20216.123NONO
Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.
Oct 5, 20216.123NONO
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&pag
Mar 6, 20187.223NONO
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=l
Mar 6, 20187.222NONO
FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01.
May 30, 20195.320NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Filerun

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2022.02.0238.01.5%00
2021.03.2626.10.7%00