First published: Thu Jan 15 2015(Updated: )
Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1041 is rated as a medium severity vulnerability due to its potential for unauthorized script execution.
To fix CVE-2015-1041, upgrade to a patched version of e107 that addresses the cross-site scripting vulnerability.
Exploitation of CVE-2015-1041 can lead to unauthorized data manipulation and compromise of user sessions.
CVE-2015-1041 affects users of e107 version 1.0.4 and potentially earlier versions that utilize the vulnerable file manager.
You can detect exploitation of CVE-2015-1041 by monitoring for unusual requests targeting the e107_admin/filemanager.php script with suspicious input.