Metinfo 7.0.0 beta is susceptible to SQL Injection in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
View the template here CVE-2019-16997.yaml
References:
https://github.com/XiaOkuoAi/XiaOkuoAi.github.io/issues/2