First published: Wed Sep 30 2020(Updated: )
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Metinfo Metinfo | =7.0.0-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20800 is a vulnerability discovered in MetInfo v7.0.0 beta that allows SQL Injection.
CVE-2020-20800 has a severity rating of 9.8 (Critical).
CVE-2020-20800 affects MetInfo v7.0.0 beta, allowing SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.
MetInfo v7.0.0 beta (7.0.0-beta) is affected by CVE-2020-20800.
To fix CVE-2020-20800 in MetInfo, update to a patched version provided by the vendor.