← Back

Exponentcms

exponentcms

Vendor: Exponentcms • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Exponentcms
1Exponentcms
Nov 21, 2024
Aug 16, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM.