CVE-2019-17676: Metinfo

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.

Affected products

  • Metinfo Metinfo: version 7.0.0 only

Published 2019-10-17. Last modified 2026-06-17.