CVE-2016-9182

Source
https://cve.org/CVERecord?id=CVE-2016-9182
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9182.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-9182
Published
2016-11-04T10:59:01.333Z
Modified
2026-07-08T10:53:59.083755Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method name in PHP reflection is case insensitive, and Exponent CMS permits undefined actions to execute by default, so an attacker can use a capitalized method name to bypass the permission check, e.g., controller=expHTMLEditor&action=preview&editor=ckeditor and controller=expHTMLEditor&action=Preview&editor=ckeditor. An anonymous user will be rejected for the former but can access the latter.

References

Affected packages

Git / github.com/exponentcms/exponent-cms

Affected ranges

Type
GIT
Repo
https://github.com/exponentcms/exponent-cms
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:exponentcms:exponent_cms:2.4.0:*:*:*:*:*:*:*",
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.4.0"
        },
        {
            "last_affected": "2.4.0"
        }
    ]
}

Affected versions

2.*
2.4.0
v2.*
v2.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9182.json"