CVE-2017-8098: CSRF
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
e107to a version that resolves this vulnerability.Fixed in 2.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8098?
CVE-2017-8098 is classified as a high severity vulnerability due to its potential for cross-site request forgery.
How do I fix CVE-2017-8098?
To fix CVE-2017-8098, users should upgrade to e107 version 2.1.5 or later where the vulnerability is patched.
What actions can be exploited via CVE-2017-8098?
CVE-2017-8098 allows attackers to exploit vulnerabilities related to installing plugins, changing meta, and modifying settings.
Is CVE-2017-8098 present in earlier versions of e107?
Yes, CVE-2017-8098 is present in e107 version 2.1.4 and earlier versions.
What types of attacks are possible due to CVE-2017-8098?
CVE-2017-8098 enables attackers to make unauthorized changes to a website by sending forged request from a malicious web page.