CVE-2015-1057: XSS
Published Jan 16, 2015
·Updated
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value.
Affected Software
1 affected component
e107 e107=2.0.0
Event History
Jan 16, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1057?
CVE-2015-1057 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2015-1057?
To fix CVE-2015-1057, update e107 CMS to version 2.0.1 or later.
3
What are the potential impacts of CVE-2015-1057?
The potential impacts of CVE-2015-1057 include unauthorized script execution and user data exposure.
4
Which software versions are affected by CVE-2015-1057?
CVE-2015-1057 affects e107 CMS version 2.0.0.
5
Who is vulnerable to CVE-2015-1057?
Any e107 CMS users running version 2.0.0 are vulnerable to CVE-2015-1057.