Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/expPaginator.php" affecting the order parameter. Impact is Information Disclosure.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9134.json"