First published: Thu Nov 03 2016(Updated: )
The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directory traversal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ExponentCMS | <=2.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7452 has a medium severity rating, indicating a moderate risk of exploitation.
To fix CVE-2016-7452, upgrade Exponent CMS to version 2.3.9 patch 2 or later.
CVE-2016-7452 allows attackers to upload malicious files to any folder on the site through directory traversal.
If you are using Exponent CMS version earlier than 2.3.9 patch 2, your version is affected by CVE-2016-7452.
The vulnerable component in CVE-2016-7452 is the Pixidou Image Editor in Exponent CMS.