header-logo
Suggest Exploit
vendor:
Exponent CMS
by:
7.5
CVSS
HIGH
Input Validation
CWE
Product Name: Exponent CMS
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

Multiple input-validation vulnerabilities in Exponent CMS

The Exponent CMS application fails to properly sanitize user-supplied input, which can lead to multiple vulnerabilities. These vulnerabilities can be exploited to steal cookie-based authentication credentials, execute arbitrary script code, manipulate the rendering of the site, compromise the application, obtain sensitive information, and access or modify data.

Mitigation:

To mitigate these vulnerabilities, it is recommended to apply the latest patches and updates provided by the vendor. Additionally, input validation should be implemented to properly sanitize user-supplied input.
Source

Exploit-DB raw data: