CVE

Id
96062  
CVE No.
CVE-2016-9242  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) content_type or (2) subtype parameter.  
Phase
Assigned (20161107)  
Votes
None (candidate not yet proposed)  
Comments