HIGH
Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) content_type or (2) subtype parameter
Published Nov 7, 2016
8.8
HIGHCVSS 3.0
EPSS 1.37%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.