First published: Fri Nov 11 2016(Updated: )
framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows remote attackers to read address information, as demonstrated by an address/show/id/1 URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exponentcms Exponent Cms | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9286 has a high severity rating due to improper access controls allowing unauthorized data access.
To fix CVE-2016-9286, update Exponent CMS to a version that addresses the access control issues.
CVE-2016-9286 allows unauthorized users to read user address information.
CVE-2016-9286 affects Exponent CMS version 2.4.0 and specifically the patch 1 version.
Any user utilizing Exponent CMS version 2.4.0patch1 is vulnerable due to insufficient access restrictions.