PT-2026-29514 · Unknown · Metinfo Cms
Egidio Romano
·
Published
2026-04-01
·
Updated
2026-05-06
·
CVE-2026-29014
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MetInfo CMS versions 7.9 through 8.1
Description
An unauthenticated PHP code injection flaw allows remote attackers to execute arbitrary code by sending crafted requests containing malicious PHP code. This issue stems from insufficient input neutralization in the execution path, enabling attackers to achieve remote code execution and gain full control over the affected server. Real-world exploitation has been observed since April 25, with a significant increase in activity starting May 1. Attackers have used this flaw to gain initial access, escalate privileges, and move laterally across networks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metinfo Cms