PT-2016-7722 · Exponent · Exponent Cms

Pang0Lin

·

Publicado

2016-11-11

·

Atualizado

2017-07-28

·

CVE-2016-9284

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Exponent CMS version 2.4.0
Description The issue allows remote attackers to read user information. This is achieved through the getUsersByJSON endpoint, specifically by appending a string to the "users/getUsersByJSON/sort/" endpoint.
Recommendations For Exponent CMS version 2.4.0, consider restricting access to the getUsersByJSON endpoint in the usersController.php file as a temporary workaround until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9284

Produtos afetados

Exponent Cms