VYPR
High severity7.2NVD Advisory· Published Sep 10, 2026

CVE-2026-73698

CVE-2026-73698

Description

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate raw array values directly into an INSERT statement without parameterization. Because the underlying PDO connection uses emulated prepared statements enabling stacked queries, attackers can manipulate the df_users_permissions table to escalate a delegated administrator account to superuser privileges, and may additionally achieve code execution via unsanitized path values passed to require_once in the logs listing component.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Afian/Fileruninferred2 versions
    <2026.3.0+ 1 more
    • (no CPE)range: <2026.3.0
    • (no CPE)range: <2026.3.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.