CVE-2026-29014 Details
Description
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
A PHP code injection vulnerability has been identified in MetInfo CMS versions 7.9, 8.0, and 8.1. This vulnerability allows remote attackers to execute arbitrary code by sending crafted requests that include malicious PHP code. The issue arises from inadequate input sanitization in the execution path, enabling remote code execution and full control over the affected server. The vulnerability is present in the 'weixinreply.class.php' file, specifically within the 'wxAdminLogin()' method, where user input from 'EventKey' and 'FromUserName' XML tags is not properly sanitized before being used in cache operations. Exploitation involves injecting PHP code through the 'EventKey' parameter, which is then executed on the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2026/Apr/1 | CVE | Mailing ListThird Party Advisory |
| https://websec.net/blog/cve-2026-29014-metinfo-cms-unauthenticated-php-code-injection-69cdc290c14a8a99e1f91b7a | CVE | ExploitThird Party Advisory |
| https://karmainsecurity.com/KIS-2026-06 | [email protected] | ExploitThird Party Advisory |
| https://www.metinfo.cn/ | [email protected] | Product |
| https://www.vulncheck.com/advisories/metinfo-cms-unauthenticated-php-code-injection-rce | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| metinfo metinfo | 7.9 8.0.0 8.1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | CVE Modified | CVE |
| Apr 3, 2026 | CVE Modified | CVE |
| Apr 1, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |