{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azyx0814filepress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zyx0814:filepress:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90879"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FilePress (\u003c= 3.0.1)"],"_cs_severities":["high"],"_cs_tags":["sqli","web-vulnerability"],"_cs_type":"threat","_cs_vendors":["zyx0814"],"content_html":"\u003cp\u003eCVE-2026-90879 describes a high-severity SQL injection vulnerability discovered in the zyx0814 FilePress software, affecting all versions up to and including 3.0.1. The flaw exists within the Publish Module, specifically in the dzz/publish/search.php file. By sending a crafted HTTP request, an unauthenticated remote attacker can inject arbitrary SQL commands via the 'orderby' or 'order' parameters. This vulnerability stems from improper neutralization of special elements used in an SQL command. As of the time of reporting, the project maintainers have not issued a patch to remediate this flaw, and public exploit code is available, increasing the risk of active exploitation. Defenders should monitor web traffic targeting the Publish Module for signs of SQL injection patterns.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows remote attackers to perform unauthorized database operations, potentially leading to data exfiltration, modification, or, depending on database permissions, remote code execution. Given the public availability of exploit code, all FilePress instances running version 3.0.1 or earlier are at high risk of compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement temporary Web Application Firewall (WAF) rules to inspect and block requests to dzz/publish/search.php containing SQL syntax characters in the 'orderby' or 'order' parameters.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious spikes in POST or GET requests to the identified vulnerable path that deviate from established baselines.\u003c/li\u003e\n\u003cli\u003eApply the vendor patch as soon as it becomes available; monitor the zyx0814 repository for version 3.0.2 or subsequent security updates.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T05:38:48Z","date_published":"2026-09-15T05:38:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-filepress-sqli/","summary":"An unpatched SQL injection vulnerability in zyx0814 FilePress versions 3.0.1 and earlier allows remote attackers to manipulate the orderby or order arguments within search.php.","title":"SQL Injection in FilePress Publish Module","url":"https://feed.craftedsignal.io/briefs/2026-09-filepress-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zyx0814:filepress:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}