CVE-2019-17418
MetInfo 7.0.0 beta - SQL Injection
Record summary
CVE-2019-17418 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHMetInfo 7.0.0 beta - SQL InjectionCVSS 7.2
MetInfo 7.0.0 beta is susceptible to SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter (a different issue than CVE-2019-16997).
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Upgrade to a patched version of MetInfo or apply the necessary security patches provided by the vendor.
Source: ProjectDiscovery