First published: Wed Jan 22 2014(Updated: )
Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the query string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | <=1.0.2 | |
e107 CMS | =0.7.0 | |
e107 CMS | =0.7.1 | |
e107 CMS | =0.7.2 | |
e107 CMS | =0.7.3 | |
e107 CMS | =0.7.4 | |
e107 CMS | =0.7.5 | |
e107 CMS | =0.7.6 | |
e107 CMS | =0.7.7 | |
e107 CMS | =0.7.8 | |
e107 CMS | =0.7.9 | |
e107 CMS | =0.7.10 | |
e107 CMS | =0.7.11 | |
e107 CMS | =0.7.12 | |
e107 CMS | =0.7.13 | |
e107 CMS | =0.7.14 | |
e107 CMS | =0.7.15 | |
e107 CMS | =0.7.16 | |
e107 CMS | =0.7.17 | |
e107 CMS | =0.7.18 | |
e107 CMS | =0.7.19 | |
e107 CMS | =0.7.20 | |
e107 CMS | =0.7.21 | |
e107 CMS | =0.7.22 | |
e107 CMS | =0.7.24 | |
e107 CMS | =0.7.26 | |
e107 CMS | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2750 has been identified as a cross-site scripting (XSS) vulnerability that can allow remote attackers to inject arbitrary web scripts or HTML.
To fix CVE-2013-2750, update your e107 CMS to version 1.0.3 or later, which addresses this vulnerability.
CVE-2013-2750 affects all e107 CMS versions prior to 1.0.3, as well as specific older versions such as 0.7.0 through 0.7.26.
By exploiting CVE-2013-2750, attackers can execute malicious scripts in the context of a user's browser session, potentially compromising data and user accounts.
There are no specific workarounds for CVE-2013-2750, so updating the software is the recommended approach to mitigate the vulnerability.