CVE-2017-14738: SQL Injection
Published Sep 29, 2017
·Updated
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
Affected Software
1 affected component
FileRun FileRun<=2017.09.18
Remediation
Event History
Sep 29, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14738?
CVE-2017-14738 has a critical severity rating of 9.8 according to CVSS 3.0.
2
How do I fix CVE-2017-14738?
To mitigate CVE-2017-14738, apply the available security patch to FileRun.
3
What vulnerability type is CVE-2017-14738?
CVE-2017-14738 is classified as a SQL Injection vulnerability.
4
Which versions of FileRun are affected by CVE-2017-14738?
FileRun versions 2017.09.18 and below are vulnerable to CVE-2017-14738.
5
What exploit does CVE-2017-14738 allow?
CVE-2017-14738 allows remote SQL injection through the metafield parameter in the metasearch module.