CVE-2023-28875: Afian Filerun

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.

Affected products

  • Afian Filerun: version 2022.02.02 only

Published 2023-12-06. Last modified 2026-06-17.