An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering is not rigorous: one can insert malicious code in the installation process to execute arbitrary commands or obtain a web shell.
| Software | From | Fixed in |
|---|---|---|
| metinfo / metinfo | 6.0.0 | 6.0.0.x |