First published: Mon Apr 24 2017(Updated: )
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8098 is classified as a high severity vulnerability due to its potential for cross-site request forgery.
To fix CVE-2017-8098, users should upgrade to e107 version 2.1.5 or later where the vulnerability is patched.
CVE-2017-8098 allows attackers to exploit vulnerabilities related to installing plugins, changing meta, and modifying settings.
Yes, CVE-2017-8098 is present in e107 version 2.1.4 and earlier versions.
CVE-2017-8098 enables attackers to make unauthorized changes to a website by sending forged request from a malicious web page.