CVE-2019-16996 Scanner

Detects 'SQL Injection' vulnerability in Metinfo affects v. 7.0.0beta.


Metinfo is an open-source CMS (Content Management System) software used for building websites and online applications. It is specifically designed for small to medium-sized businesses that require a simple yet robust platform for their web solutions. Metinfo provides a wide range of features, including different modules, templates, SEO settings, and so on. It is widely used across various industries, including e-commerce, education, healthcare, and government agencies. The software is highly customizable, which makes it a popular solution for web developers worldwide.

The Metinfo software is prone to a critical vulnerability, CVE-2019-16996 discovered in its 7.0.0beta version. This vulnerability stems from a SQL injection attack on the admin/product_admin.class.php file. The vulnerability can be exploited by an attacker with admin access to the product_admin page and can result in data leakage, data manipulation, website defacement, or even a complete system takeover. This vulnerability requires no authentication, can be exploited remotely, and has a high severity rating, making it a significant challenge for users of the Metinfo CMS.

When an attacker gains access to a system through this vulnerability, they are free to cause havoc on the target system. They can compromise sensitive data, access customer information, manipulate orders and prices, or even take over the entire system. This vulnerability can lead to a severe loss of customer and business trust, data breaches, negative publicity, and legal repercussions. Exploitation of the vulnerability can be a catastrophic event for any organization, leading to a significant loss of business reputation and financial losses.

