Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/exponentcms/exponent-cms/releases/tag/v2.4.0 | third party advisory release notes |
http://www.exponentcms.org/news/patch-1-released-for-v2-3-9 | patch vendor advisory |