Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

404Notfound

#26018de 53,622
9.8CVSS total
Vulnerabilidades · 1
PT-2017-18053
9.8
2017-04-22
Exponent · Exponent Cms · CVE-2017-7991
**Name of the Vulnerable Software and Affected Versions** Exponent CMS versions 2.4.1 and earlier **Description** The issue concerns a SQL injection vulnerability. It occurs via a base64 serialized API key in the `apikey` parameter within the `api` function of `framework/modules/eaas/controllers/eaasController.php`. **Recommendations** For Exponent CMS versions 2.4.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.