CVE-2017-7991
22.04.2017, 01:59
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.
Vendor | Product | Version |
---|---|---|
exponentcms | exponent_cms | 𝑥 ≤ 2.4.1 |
𝑥
= Vulnerable software versions
References