Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php" affecting the version parameter. Impact is Information Disclosure.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9135.json"