Record summary

CVE-2019-17418 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHMetInfo 7.0.0 beta - SQL InjectionCVSS 7.2

MetInfo 7.0.0 beta is susceptible to SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter (a different issue than CVE-2019-16997).

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Upgrade to a patched version of MetInfo or apply the necessary security patches provided by the vendor.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2019metinfosqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:metinfo:metinfo:7.0.0:beta:*:*:*:*:*:*

Source: ProjectDiscovery

References

2