First published: Thu Oct 10 2019(Updated: )
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Metinfo Metinfo | =7.0.0-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-17419 is high with a score of 7.2.
The SQL injection occurs via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter in MetInfo 7.0.
The affected software version of CVE-2019-17419 is MetInfo 7.0.0-beta.
Yes, the issue has been fixed in later versions of MetInfo.
The CWE ID for CVE-2019-17419 is CWE-89.