Critical severity9.1NVD Advisory· Published Nov 11, 2016· Updated May 6, 2026
CVE-2016-9272
CVE-2016-9272
Description
A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/exponentcms/exponent-cms/commit/fffb2038de4c603931b785a4c3ec69cfd06181banvdIssue TrackingPatchThird Party Advisory
- www.securityfocus.com/bid/94261nvdThird Party AdvisoryVDB Entry
- exponentcms.lighthouseapp.com/projects/61783/tickets/1394-blind-sql-injection-vulnerability-in-exponent-cms-240-4nvdVendor Advisory
- exponentcms.lighthouseapp.com/projects/61783/tickets/1395-blind-sql-injection-vulnerability-in-exponent-cms-240-5nvdVendor Advisory
News mentions
0No linked articles in our index yet.