« Back to list

Metinfo Project

Metinfo Project Metinfo: vulnerabilities and CVEs

Metinfo Project Metinfo has 4 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2017-11718Medium (6.1)0.66%—Jul 28, 2017
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.
CVE-2017-11717High (7.5)1.2%—Jul 28, 2017
MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated…
CVE-2017-11716Medium (6.1)0.65%—Jul 28, 2017
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.
CVE-2017-11715Critical (9.8)1.5%—Jul 28, 2017
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after…