CVE-2013-7305: Medium severity e107 e107 vulnerability
fpw.php in e107 through 1.0.4 does not check the userban field, which makes it easier for remote attackers to reset passwords by sending a pwsubmit request and leveraging access to the e-mail account of a banned user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7305?
CVE-2013-7305 is classified as a high severity vulnerability due to its potential for password reset exploitation by remote attackers.
How do I fix CVE-2013-7305?
To fix CVE-2013-7305, upgrade to a version of e107 that is later than 1.0.4 which includes security patches addressing this vulnerability.
What versions are affected by CVE-2013-7305?
CVE-2013-7305 affects e107 versions from 0.7.0 up to 1.0.4.
What is the impact of CVE-2013-7305 on e107 CMS?
The impact of CVE-2013-7305 allows unauthorized password reset requests, which could compromise user accounts of banned users.
Is CVE-2013-7305 exploitable remotely?
Yes, CVE-2013-7305 is exploitable remotely, allowing attackers to leverage access to the e-mail accounts of banned users for resetting passwords.