CVE-2018-7735: Afian Filerun

High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.

Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&page=list_filetypes request.

Affected products

  • Afian Filerun: up to and including 2017.09.25

Published 2018-03-06. Last modified 2026-06-17.