Critical severity9.8NVD Advisory· Published May 24, 2019· Updated Jun 17, 2026
CVE-2016-8898
CVE-2016-8898
Description
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:exponentcms:exponent_cms:2.3.9:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:exponentcms:exponent_cms:2.3.9:*:*:*:*:*:*:*
- (no CPE)range: <2.3.9
- Exponent/Exponent CMSdescription
Patches
Vulnerability mechanics
References
2- github.com/exponentcms/exponent-cms/commit/99636b2118cd9af4eb9920f6b6c228bd824593d2nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2016/09/30/5nvdExploitMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.