CVE-2018-12530: Metinfo

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files via a flienamecsv=../ directory traversal. This can be exploited via CSRF.

Affected products

  • Metinfo Metinfo: version 6.0.0 only

Published 2018-06-18. Last modified 2026-06-17.