SQL Injection Vulnerability in Exponent CMS by Exponent
CVE-2016-7780
9.8CRITICAL
What is CVE-2016-7780?
An SQL injection vulnerability exists in the Exponent CMS through the cron/find_help.php file. This flaw allows remote attackers to exploit the 'version' parameter and execute arbitrary SQL commands, potentially compromising the database and exposing sensitive information. Users are advised to update to patched versions to mitigate these risks.
