CVE-2016-9272

CRITICAL

Exponent CMS <2.4.0 - SQL Injection

Title source: llm
STIX 2.1

Description

A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.

Scores

CVSS v3 9.1
EPSS 0.0085
EPSS Percentile 74.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-89
Status published
Products (1)
exponentcms/exponent_cms < 2.4.0
Published Nov 11, 2016
Tracked Since Feb 18, 2026