Back
CVE-2016-9019
CRITICAL
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.
Published: Mar 7, 2017
Modified: Jun 17, 2026
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| exponentcms | exponent_cms | * |
GitHub Security Advisory GHSA-xh34-jr4v-w5wr
SQL injection vulnerability in the activate_address function in framework/modules/addressbook...
References (8)
- http://forums.exponentcms.org/index.php?p=/discussion/comment/1591#Comment_1591 Vendor Advisory
- http://packetstormsecurity.com/files/139484/Exponent-CMS-2.3.9-SQL-Injection.html Patch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Nov/12 Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/97240
- http://forums.exponentcms.org/index.php?p=/discussion/comment/1591#Comment_1591 Vendor Advisory
- http://packetstormsecurity.com/files/139484/Exponent-CMS-2.3.9-SQL-Injection.html Patch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Nov/12 Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/97240
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
3.30%
Top 13% most likely to be exploited
Threat Score
40.2 / 100
Data Sources
NVD
EPSS
GitHub