CVE-2018-12531: Metinfo

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271.

Affected products

  • Metinfo Metinfo: version 6.0.0 only

Published 2018-06-18. Last modified 2026-06-17.