Improper Input Validation in Exponent CMS Affects Users
CVE-2016-9021

9.8CRITICAL

Key Information:

Vendor
CVE Published:
31 December 2020

What is CVE-2016-9021?

Exponent CMS prior to version 2.6.0 features a significant flaw in the storeController.php file, where improper input validation can potentially allow unauthorized access or data manipulation. This vulnerability poses risks to the integrity and security of web applications utilizing this content management system. Users are strongly advised to upgrade to the latest version to mitigate these risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.