CVE-2014-8690 | Exponent CMS up to 2.2.1 index.php src cross site scripting (Patch 130382 / EDB-36059)
A vulnerability, which was classified as problematic, was found in Exponent CMS up to 2.2.1. Affected is an unknown function of the file index.php. The manipulation of the argument src leads to cross site scripting.
This vulnerability is traded as CVE-2014-8690. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.