PT-2016-7714 · Exponent · Exponent Cms
Fyth
·
Published
2016-11-07
·
Updated
2016-11-29
·
CVE-2016-9242
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Exponent CMS version 2.4.0
Description
The issue concerns SQL injection vulnerabilities in the update method within the expRatingController.php file of Exponent CMS. These vulnerabilities allow remote authenticated users to execute arbitrary SQL commands by manipulating specific parameters. The vulnerable parameters are
content type and subtype.Recommendations
For Exponent CMS version 2.4.0, consider restricting access to the update method in expRatingController.php to prevent exploitation until a fix is available. As a temporary workaround, avoid using the
content type and subtype parameters in the affected API endpoint until the issue is resolved.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exponent Cms