← Vulnerability feed

Vulnerability record · CVE-2019-16997 · published 30 September 2019

CVE-2019-16997: Metinfo admin language export SQL injection

MMetinfo · Metinfo

Metinfo 7.0.0beta contains a SQL injection in app/system/language/admin/language_general.class.php, reached through the admin/?n=language&c=language_general&a=doExportPack endpoint via the appno parameter. An attacker who can reach that admin function can inject SQL into the backend database, which matters because it exposes or alters data behind the CMS.

7.2 CVSS 3.1 High EPSS 49% · top 1.1% CWE-89 · SQL injection
7.2CVSS 3.1 base score, v2 6.5
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 7.2 with high confidentiality, integrity and availability impact, plus public exploit references and a very high EPSS percentile, though exploitation requires an authenticated admin position.

What it is

Metinfo 7.0.0beta contains a SQL injection in app/system/language/admin/language_general.class.php, reached through the admin/?n=language&c=language_general&a=doExportPack endpoint via the appno parameter. An attacker who can reach that admin function can inject SQL into the backend database, which matters because it exposes or alters data behind the CMS.

Impact

Successful exploitation gives the attacker database read and write capability through the injected query, with potential full compromise of confidentiality, integrity and availability of the affected Metinfo data. The CVSS vector rates all three impacts as high.

Attack surface

The flaw is network reachable (AV:N) but requires high privileges (PR:H), meaning the attacker must already hold an administrative session or credentials for the language export function. No user interaction is required (UI:N).

Exploitation

No CISA KEV listing and no ransomware association are recorded, but the references carry an Exploit tag and EPSS is 0.49398 (98.8th percentile), indicating public exploit material and elevated likelihood of attempted exploitation.

What to do

  • Apply the vendor fix for Metinfo 7.0.0beta or upgrade to a release where this SQL injection is corrected; if no patch is available, treat the affected version as unsupported.
  • Restrict access to the admin interface and specifically the language_general doExportPack function to trusted networks or VPN, not the public internet.
  • Enforce least privilege on Metinfo admin accounts and remove or disable unused administrator logins.
  • Deploy a WAF rule that inspects the appno parameter on admin/?n=language&c=language_general&a=doExportPack for SQL metacharacters.
  • Audit database accounts used by Metinfo and remove unnecessary write or DDL privileges.

Detection

  • Monitor web logs for requests to admin/?n=language&c=language_general&a=doExportPack with unusual or SQL-like appno values.
  • Alert on SQL error strings or unexpected query failures in Metinfo application and database logs.
  • Baseline normal admin language export activity and flag exports from new source IPs or outside normal admin hours.
  • Review database audit logs for anomalous SELECT, UNION or stacked query patterns originating from the web application account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/XiaOkuoAi/XiaOkuoAi.github.io/issues/2 ExploitIssue TrackingThird Party Advisory
https://github.com/XiaOkuoAi/XiaOkuoAi.github.io/issues/2 ExploitIssue TrackingThird Party Advisory

Track CVE-2019-16997 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2019-16997), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.