CVE-2017-7991

Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:exponentcms:exponent_cms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:33

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2017/Apr/78 - Exploit, Third Party Advisory () http://seclists.org/fulldisclosure/2017/Apr/78 - Exploit, Third Party Advisory
References () https://gist.github.com/404notf0und/ab59234d71fbf35b4926ffd646324f29 - Exploit, Third Party Advisory () https://gist.github.com/404notf0und/ab59234d71fbf35b4926ffd646324f29 - Exploit, Third Party Advisory
References () https://github.com/exponentcms/exponent-cms/commit/67a9c2f0229de120431f3eecb0f5017075517105 - () https://github.com/exponentcms/exponent-cms/commit/67a9c2f0229de120431f3eecb0f5017075517105 -
References () https://packetstormsecurity.com/files/142258/Exponent-CMS-2.4.1-SQL-Injection.html - Exploit, Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/142258/Exponent-CMS-2.4.1-SQL-Injection.html - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2017-04-22 01:59

Updated : 2024-11-21 03:33


NVD link : CVE-2017-7991

Mitre link : CVE-2017-7991

CVE.ORG link : CVE-2017-7991


JSON object : View

Products Affected

exponentcms

  • exponent_cms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')