exponentcms/exponent-cms

ExponentCMS v2.6.0 unauthticate sql injection

Closed this issue · 3 comments

I found an unauthticate sql injection for ExponentCMS v2.6.0 (the latest version at this time), for more details.
https://github.com/pang0lin/CVEproject/blob/main/ExponentCMS_v2.6.0_sqli.md

I have a fix, have you opened a CVE report?

Not yet, it is in processing

Fix Commit 34dd490