CVE-2020-19305

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
03/08/2021
Last modified:
05/10/2022

Description

An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:metinfo:metinfo:7.0.0:-:*:*:*:*:*:*