Vulnerability record · CVE-2019-16997 · published 30 September 2019
CVE-2019-16997: Metinfo admin language export SQL injection
MMetinfo · Metinfo
Metinfo 7.0.0beta contains a SQL injection in app/system/language/admin/language_general.class.php, reached through the admin/?n=language&c=language_general&a=doExportPack endpoint via the appno parameter. An attacker who can reach that admin function can inject SQL into the backend database, which matters because it exposes or alters data behind the CMS.
Description
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high confidentiality, integrity and availability impact, plus public exploit references and a very high EPSS percentile, though exploitation requires an authenticated admin position.
What it is
Metinfo 7.0.0beta contains a SQL injection in app/system/language/admin/language_general.class.php, reached through the admin/?n=language&c=language_general&a=doExportPack endpoint via the appno parameter. An attacker who can reach that admin function can inject SQL into the backend database, which matters because it exposes or alters data behind the CMS.
Impact
Successful exploitation gives the attacker database read and write capability through the injected query, with potential full compromise of confidentiality, integrity and availability of the affected Metinfo data. The CVSS vector rates all three impacts as high.
Attack surface
The flaw is network reachable (AV:N) but requires high privileges (PR:H), meaning the attacker must already hold an administrative session or credentials for the language export function. No user interaction is required (UI:N).
Exploitation
No CISA KEV listing and no ransomware association are recorded, but the references carry an Exploit tag and EPSS is 0.49398 (98.8th percentile), indicating public exploit material and elevated likelihood of attempted exploitation.
What to do
- Apply the vendor fix for Metinfo 7.0.0beta or upgrade to a release where this SQL injection is corrected; if no patch is available, treat the affected version as unsupported.
- Restrict access to the admin interface and specifically the language_general doExportPack function to trusted networks or VPN, not the public internet.
- Enforce least privilege on Metinfo admin accounts and remove or disable unused administrator logins.
- Deploy a WAF rule that inspects the appno parameter on admin/?n=language&c=language_general&a=doExportPack for SQL metacharacters.
- Audit database accounts used by Metinfo and remove unnecessary write or DDL privileges.
Detection
- Monitor web logs for requests to admin/?n=language&c=language_general&a=doExportPack with unusual or SQL-like appno values.
- Alert on SQL error strings or unexpected query failures in Metinfo application and database logs.
- Baseline normal admin language export activity and flag exports from new source IPs or outside normal admin hours.
- Review database audit logs for anomalous SELECT, UNION or stacked query patterns originating from the web application account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/XiaOkuoAi/XiaOkuoAi.github.io/issues/2 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/XiaOkuoAi/XiaOkuoAi.github.io/issues/2 | ExploitIssue TrackingThird Party Advisory |
Track CVE-2019-16997 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-16997), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.