Vulnerability Scanner Plugin for SQL Injections on the Metinfo Homepage Is Released
Oct 17 2018
Content
Target customers: Metinfo users. Features released: On Oct 16, 2018, the emergency response center identified SQL injection as a potential threat that can exploit a new vulnerability on the homepage of Metinfo 6.1.2. Attackers can exploit the vulnerability to obtain sensitive data and unauthorized access to a website database using nefarious SQL statements. Vulnerability description: In the vulnerability file: metinfo6.1.2/app/system/message/web/message.class.php, the id parameter is incorrectly filtered, which results in SQL injections. Vulnerability severity: High. Vulnerability name: CNVD-2018-20024. Attack scope: Metinfo 6.1.2.