SQL Injection Flaw in Exponent CMS by Exponent
CVE-2016-7782
9.8CRITICAL
What is CVE-2016-7782?
An SQL injection vulnerability exists in Exponent CMS versions 2.3.9 and earlier due to improper sanitization of the 'src' parameter in the 'framework/core/models/expConfig.php' file. This flaw allows remote attackers to execute arbitrary SQL commands, potentially compromising the integrity of the application's database and exposing sensitive information.
