Exponent · Exponent Cms · CVE-2016-9135
**Name of the Vulnerable Software and Affected Versions**
Exponent CMS version 2.3.9
**Description**
The issue affects the "/framework/modules/help/controllers/helpController.php" file, specifically the `version` parameter, allowing for SQL injection. This can lead to information disclosure.
**Recommendations**
For Exponent CMS version 2.3.9, consider restricting access to the "/framework/modules/help/controllers/helpController.php" file until a patch is available. As a temporary workaround, avoid using the `version` parameter in the affected controller to minimize the risk of exploitation.