Metinfo
by Metinfo
Source repositories
CVEs (64)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-29014 | Cri | 0.67 | 9.8 | 0.42 | Apr 1, 2026 | MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution… | ||
| CVE-2022-23335 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2022 | Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter. | ||
| CVE-2022-22295 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2022 | Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter. | ||
| CVE-2020-21127 | Cri | 0.64 | 9.8 | 0.02 | Sep 15, 2021 | MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel. | ||
| CVE-2020-19305 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2021 | An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges. | ||
| CVE-2020-18175 | Cri | 0.64 | 9.8 | 0.02 | Jul 30, 2021 | SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php. | ||
| CVE-2020-21133 | Cri | 0.64 | 9.8 | 0.02 | Jul 12, 2021 | SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid. | ||
| CVE-2020-21132 | Cri | 0.64 | 9.8 | 0.02 | Jul 12, 2021 | SQL Injection vulnerability in Metinfo 7.0.0beta in index.php. | ||
| CVE-2020-20800 | Cri | 0.64 | 9.8 | 0.02 | Sep 30, 2020 | An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI. | ||
| CVE-2019-17553 | Cri | 0.64 | 9.8 | 0.02 | Oct 14, 2019 | An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI. | ||
| CVE-2018-12531 | Cri | 0.64 | 9.8 | 0.02 | Jun 18, 2018 | An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271. | ||
| CVE-2017-11715 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2017 | job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php. | ||
| CVE-2020-20907 | Cri | 0.59 | 9.1 | 0.02 | May 24, 2021 | MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php. | ||
| CVE-2022-44849 | Hig | 0.57 | 8.8 | 0.00 | Dec 7, 2022 | A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account. | ||
| CVE-2020-21126 | Hig | 0.57 | 8.8 | 0.01 | Sep 15, 2021 | MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo. | ||
| CVE-2020-18157 | Hig | 0.57 | 8.8 | 0.01 | Jul 30, 2021 | Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php. | ||
| CVE-2019-17676 | Hig | 0.57 | 8.8 | 0.01 | Oct 17, 2019 | app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI. | ||
| CVE-2019-13969 | Hig | 0.57 | 8.8 | 0.01 | Jul 19, 2019 | Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request. | ||
| CVE-2017-12789 | Hig | 0.57 | 8.8 | 0.01 | May 10, 2019 | Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state. | ||
| CVE-2018-14420 | Hig | 0.57 | 8.8 | 0.01 | Jul 20, 2018 | MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI. |
- risk 0.67cvss 9.8epss 0.42
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution…
- risk 0.64cvss 9.8epss 0.02
Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter.
- risk 0.64cvss 9.8epss 0.02
Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter.
- risk 0.64cvss 9.8epss 0.02
MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
- risk 0.64cvss 9.8epss 0.02
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271.
- risk 0.64cvss 9.8epss 0.01
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php.
- risk 0.59cvss 9.1epss 0.02
MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.
- risk 0.57cvss 8.8epss 0.01
MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.
- risk 0.57cvss 8.8epss 0.01
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.
- risk 0.57cvss 8.8epss 0.01
Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.
- risk 0.57cvss 8.8epss 0.01
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.
- risk 0.57cvss 8.8epss 0.01
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
Page 1 of 4