Exponent CMS是Exponent公司的一个提供页面管理与模块化内容编辑能力的网站内容管理系统。 Exponent CMS 2.6版本存在跨站脚本漏洞,该漏洞源于文本编辑端点中的标题和文本块参数存在存储型跨站脚本漏洞,允许认证攻击者注入恶意脚本,攻击者可以注入带有嵌入式SVG onload事件的iframe有效载荷执行任意JavaScript,同时应用程序在响应中暴露数据库凭据,且认证端点缺乏暴力破解保护。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Exponentcms | Exponent CMS | ≤ 2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Exponentcms | Exponent CMS | 0 ~ 2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet