Beveiligingsadvies

CVE-2016-9287

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2016-11-15 11:00:00
Laatst bijgewerkt 2024-08-06 02:42:11
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection.