Object Injection Vulnerability in Exponent CMS by Exponent
CVE-2016-8900
9.8CRITICAL
What is CVE-2016-8900?
Exponent CMS version 2.3.9 contains an object injection vulnerability in the expTagController.php file within the core module framework. This flaw arises during the handling of the change_tags functionality, potentially allowing an attacker to manipulate the application state and execute arbitrary code. Proper sanitization and validation measures must be implemented to mitigate this risk effectively.
