VYPR

Metinfo

by Metinfo

Source repositories

CVEs (64)

  • CVE-2018-9934HigApr 10, 2018
    risk 0.57cvss 8.8epss 0.01

    The reset-password feature in MetInfo 6.0 allows remote attackers to change arbitrary passwords via vectors involving a Host HTTP header that is modified to specify a web server under the attacker's control.

  • CVE-2017-11347HigJul 17, 2017
    risk 0.57cvss 8.8epss 0.02

    Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.

  • CVE-2019-7718HigFeb 11, 2019
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP code via admin/index.php?n=databack&c=index&a=dogetsql&tables=<?php and admin/databack/bakup_tables.php?2=file_put_contents URIs…

  • CVE-2018-7271HigFeb 21, 2018
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering is not rigorous: one can insert malicious code in the installation process to execute arbitrary commands or obtain a web shell.

  • CVE-2019-17418HigOct 10, 2019
    risk 0.51cvss 7.2epss 0.49

    An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.

  • CVE-2019-16997HigSep 30, 2019
    risk 0.51cvss 7.2epss 0.49

    In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.

  • CVE-2025-63551HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This flaw stems from a defect in the XML parsing logic, which allows an attacker to construct a malicious…

  • CVE-2020-20981HigAug 12, 2021
    risk 0.49cvss 7.5epss 0.01

    A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.

  • CVE-2020-19304HigAug 3, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.

  • CVE-2020-20585HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.02

    A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.

  • CVE-2017-11717HigJul 28, 2017
    risk 0.49cvss 7.5epss 0.01

    MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated by the login/findpass page.

  • CVE-2017-11500HigJul 20, 2017
    risk 0.49cvss 7.5epss 0.02

    A directory traversal vulnerability exists in MetInfo 5.3.17. A remote attacker can use ..\ to delete any .zip file via the filenames parameter to /admin/system/database/filedown.php.

  • CVE-2019-16996HigSep 30, 2019
    risk 0.48cvss 7.2epss 0.12

    In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.

  • CVE-2020-21131HigJul 12, 2021
    risk 0.47cvss 7.2epss 0.01

    SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.

  • CVE-2019-17419HigOct 10, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.

  • CVE-2018-13024HigJun 29, 2018
    risk 0.47cvss 7.2epss 0.01

    Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an editor upload action.

  • CVE-2017-12790MedMay 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in the login state.

  • CVE-2018-12530MedJun 18, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files via a flienamecsv=../ directory traversal. This can be exploited via CSRF.

  • CVE-2025-60454MedOct 3, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the image management module, specifically in the app\system\img\admin\img_admin.class.php component. The vulnerability allows attackers to upload…

  • CVE-2025-60453MedOct 3, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the column management module, specifically in the app\system\column\admin\index.class.php component. The vulnerability allows attackers to upload…