First published: Fri Nov 11 2016(Updated: )
getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exponentcms Exponent Cms | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9284 is classified as a medium severity vulnerability due to its potential for unauthorized information disclosure.
To fix CVE-2016-9284, upgrade Exponent CMS to a version higher than 2.4.0 where the vulnerability has been resolved.
CVE-2016-9284 is an information disclosure vulnerability that allows remote attackers to read user information.
CVE-2016-9284 affects Exponent CMS version 2.4.0.
Yes, CVE-2016-9284 can be exploited remotely by attackers to access user information.