First published: Fri Jan 02 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in the AdminObserver function in e107_admin/users.php in e107 2.0 alpha2 allows remote attackers to hijack the authentication of administrators for requests that add users to the administrator group via the id parameter in an admin action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E107 E107 | =2.0-alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.