← Back to CVE List

CVE-2017-7991

Published: 2017-04-22T01:59Z
Last Modified: 2024-11-21T03:33Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt