SQL Injection Vulnerability in Exponent CMS by Exponent
CVE-2016-9087
9.8CRITICAL
What is CVE-2016-9087?
A SQL injection vulnerability exists in Exponent CMS versions 2.3.9 and earlier, specifically in the filedownloadController.php file. This flaw permits remote attackers to manipulate the fileid parameter and execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the database. Users of Exponent CMS are advised to review their systems for exposure and apply appropriate updates to mitigate the risk.
