CVE-2026-108900 | Exponent CMS up to 3.0.2patch2 XML-RPC xmlrpc.php userLogin sql injection
A vulnerability categorized as critical has been discovered in Exponent CMS up to 3.0.2patch2. Affected is the function userLogin of the file xmlrpc.php of the component XML-RPC. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-108900. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More