Security Advisory

CVE-2015-8684

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-18 17:00:00
Last updated 2024-08-06 08:29:20
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.