SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.026
EPSS Ranking 83.1%