Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-8133 โ€” AI Deep Analysis Summary

CVSS 7.3 ยท High

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Nature**: `admin.php` parameter order manipulation โ†’ **SQL Injection** ๐Ÿ’ฅ **Consequence**: Remote attackers can read/modify the database ๐Ÿ“‰ Causing information leakage or damage

Q2Root Cause? (CWE/Flaw)

๐Ÿ” **Root Cause**: Parameter order manipulation โš ๏ธ Suspected **CWE-89**: SQL Injection ๐Ÿ“Œ Vulnerability Point: Unknown function in `dzz/shares/admin.php`

Q3Who is affected? (Versions/Components)

๐ŸŽฏ **Affected Versions**: zyx0814 FilePress โ‰ค **2.2.0** ๐Ÿงฉ **Affected Component**: Shares Filelist API โžก๏ธ `admin.php`

Q4What can hackers do? (Privileges/Data)

๐Ÿ‘ค **Privileges**: No login required ๐Ÿšช ๐Ÿ—ƒ๏ธ **Accessible Data**: Database content ๐Ÿ“‰ Risk: Data theft, tampering, or destruction

Q5Is exploitation threshold high? (Auth/Config)

โœ… **Low Exploitation Threshold** ๐ŸŒ **Remote** โœ”๏ธ ๐Ÿ”“ **No Authentication Required** (PR:N / UI:N) โš™๏ธ Triggerable with default configuration

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿงจ **Existing Exploit Available**! ๐Ÿ“‚ PoC on GitHub ๐Ÿ”— `Web-Security-Research/FilePress/Shares-API-PreAuth-SQLi` ๐Ÿ“ข Exploitation code is publicly available ๐Ÿšจ

Q7How to self-check? (Features/Scanning)

๐Ÿ”Ž **Self-Check Method**: - Check if using FilePress โ‰ค 2.2.0 โ— - Locate `dzz/shares/admin.php` ๐Ÿ“ - Search for unfiltered parameter concatenation ๐Ÿงต - Test for abnormal responses using known requests ๐Ÿงช

Q8Is it fixed officially? (Patch/Mitigation)

๐Ÿ›ก๏ธ **Officially Patched** โœ… ๐Ÿ“Œ Patch Hash: `e20ec58414103f781858f2951d178e19b1736664` ๐Ÿ”— GitHub commit & PR published ๐Ÿ”ง

Q9What if no patch? (Workaround)

โš ๏ธ **Before Patching**: - Restrict access to `admin.php` ๐Ÿšง IP whitelist - Disable Shares Filelist API โŒ - Use Web Application Firewall to block suspicious parameters ๐Ÿงฑ

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **High Priority**! ๐Ÿ“ˆ CVSS: **6.3** (L/L/L) ๐Ÿ“ข Easy to exploit + Public Exploit โž• Remote Unauthenticated ๐Ÿ’ก Recommendation: Apply patch immediately or implement temporary protection ๐Ÿšจ