CVE-2011-4920: XSS
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.26, and other versions before 1.0.0, allow remote attackers to inject arbitrary web script or HTML via the URL to (1) e107images/thumb.php or (2) rate.php, (3) resendname parameter to e107admin/users.php, and (4) link BBCode in user signatures.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4920?
CVE-2011-4920 has been rated as medium severity due to its potential to allow unauthorized script execution.
How do I fix CVE-2011-4920?
To fix CVE-2011-4920, upgrade to e107 version 1.0.0 or later to mitigate the XSS vulnerabilities.
What are the vulnerable components in CVE-2011-4920?
CVE-2011-4920 affects e107 version 0.7.26 and includes vulnerabilities in e107_images/thumb.php, rate.php, and the resend_name parameter of e107_admin/users.php.
Who is impacted by CVE-2011-4920?
Remote attackers can exploit CVE-2011-4920 to inject arbitrary JavaScript or HTML, impacting users of vulnerable e107 installations.
What are the potential consequences of CVE-2011-4920?
The XSS vulnerabilities in CVE-2011-4920 could lead to data theft, session hijacking, and unauthorized actions taken on behalf of users.