Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-23047

Description

Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

POC

Reference

- https://exponentcms.lighthouseapp.com/projects/61783/tickets/1459

- https://fluidattacks.com/advisories/franklin/

Github

No PoCs found on GitHub currently.