Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqc8-9v27-r965

Опубликовано: 01 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

EPSS

Процентиль: 99%
0.41576
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
4 месяца назад

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

CVSS3: 9.8
fstec
5 месяцев назад

Уязвимость функции wxAdminLogin() CMS-системы Metinfo, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.41576
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94