PT-2022-15937 · Metinfo · Metinfo
Published
2022-02-14
·
Updated
2022-02-22
·
CVE-2022-23335
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Metinfo version 7.5.0
Description
The issue is a SQL injection vulnerability found in the language general.class.php file via the
doModifyParameter function. This vulnerability was discovered in Metinfo version 7.5.0.Recommendations
For Metinfo version 7.5.0, consider restricting access to the
language general.class.php file or the doModifyParameter function until a patch is available. As a temporary workaround, avoid using the doModifyParameter function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metinfo