FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.063
EPSS Ranking 90.5%