CVE-2010-4757: XSS
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnewstitle parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obtained from third party information. NOTE: this might be the same as CVE-2009-4083.1 or CVE-2011-0457.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4757?
The severity of CVE-2010-4757 is classified as medium due to its potential impact through cross-site scripting (XSS).
How do I fix CVE-2010-4757?
To fix CVE-2010-4757, upgrade to e107 version 0.7.23 or later, which patches the vulnerability.
What systems are affected by CVE-2010-4757?
CVE-2010-4757 affects multiple versions of the e107 CMS, including versions prior to 0.7.23.
Can CVE-2010-4757 lead to data theft?
Yes, CVE-2010-4757 can allow attackers to execute arbitrary scripts in users' browsers, potentially leading to data theft.
Is CVE-2010-4757 still a concern for users of e107 CMS?
Yes, users still running vulnerable versions of e107 CMS should consider upgrading to mitigate the risks associated with CVE-2010-4757.