CVE-2016-9285
11.11.2016, 22:59
framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modified id number, as demonstrated by address/edit/id/1, related to an "addresses, countries, and regions" issue.Enginsight
Vendor | Product | Version |
---|---|---|
exponentcms | exponent_cms | 2.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References