Security Exponent CMS 2.3.5 File Upload Cross Site Scripting April 21, 2016 007admin Leave a comment Exponent CMS version 2.3.5 suffers from a file upload vulnerability that allows for cross site scripting.