First published: Wed Feb 09 2022(Updated: )
Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session.
Credit: help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Exponentcms Exponent Cms | =2.6.0-patch2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.