CVE-2022-30469

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
06/06/2022
Last modified:
14/06/2022

Description

In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:afian:filerun:2022.02.02:*:*:*:*:*:*:*