CVE-2022-47532: Filerun

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.

Affected products

  • Filerun Filerun: version 20220519 only

Published 2023-12-22. Last modified 2026-06-17.