AfianCVEs & Vulnerabilities

14 CVEs affecting Afian products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

filerun 14
CVE-2023-28876MEDIUM

A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on files uploaded by other users.

6 Dec 2023
4.3
CVSS
CVE-2023-28875MEDIUM

A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.

6 Dec 2023
5.4
CVSS
CVE-2022-30469HIGH

In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

7 Jun 2022
8.8
CVSS
CVE-2022-30470CRITICAL

In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user.

2 Jun 2022
9.8
CVSS
CVE-2021-35506MEDIUM

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

5 Oct 2021
6.1
CVSS
CVE-2021-35505HIGH

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.

5 Oct 2021
7.2
CVSS
CVE-2021-35504HIGH

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.

5 Oct 2021
7.2
CVSS
CVE-2021-35503MEDIUM

Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.

5 Oct 2021
6.1
CVSS
CVE-2019-12905MEDIUMpoc

FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI. This issue has been fixed in FileRun 2019.06.01.

20 Jun 2019
6.1
CVSS
CVE-2019-12459MEDIUM

FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01.

30 May 2019
5.3
CVSS
CVE-2019-12458MEDIUM

FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01.

30 May 2019
5.3
CVSS
CVE-2019-12457MEDIUM

FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01.

30 May 2019
5.3
CVSS
CVE-2018-7735HIGH

Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&page=list_filetypes request.

6 Mar 2018
7.2
CVSS
CVE-2018-7734HIGH

Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=list request.

6 Mar 2018
7.2
CVSS
← PrevPage 1 / 1Next →
Afian CVEs & Vulnerabilities — 14 Tracked