CVE-2020-20907

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
24/05/2021
Last modified:
05/10/2022

Description

MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:metinfo:metinfo:7.0.0:beta:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*