Impact
This flaw in the FilePress Publish module permits an attacker to alter the orderby and order query parameters in dzz/publish/search.php, resulting in arbitrary SQL injection. The injection can disclose confidential data, modify database records, or perform destructive database operations, thereby compromising the confidentiality and integrity of the application’s data. The vulnerability is exploitable remotely and a public exploit is available, meaning it can be leveraged without any special access.
Affected Systems
The affected product is FilePress by zyx0814. Versions up to and including 3.0.1 are vulnerable. The flaw resides in the Publish module’s dzz/publish/search.php file. No specific later versions are known to be unaffected until a patch is released.
Risk and Exploitability
The CVSS base score of 6.9 indicates medium severity while the EPSS score of < 1% suggests a low yet non‑zero likelihood of exploitation. Because the attack is remote and a public exploit exists, the risk remains real. The vulnerability is not yet catalogued in the CISA KEV list.
OpenCVE Enrichment