
We found results for “”
CVE-2016-9021
Date: December 30, 2020
Exponent CMS before 2.6.0 has improper input validation in storeController.php. After conducting further research, Mend has determined that all versions of Exponent CMS up to version v2.4.0 are vulnerable to CVE-2016-9026.
Language: PHP
Severity Score
Related Resources (4)
Severity Score
Weakness Type (CWE)
Improper Input Validation
CWE-20CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |