CVE-2018-15901: CSRF
Published Aug 28, 2018
·Updated
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
Affected Software
1 affected component
e107 e107=2.1.8
Event History
Aug 28, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-15901?
CVE-2018-15901 is a vulnerability in e107 2.1.8 that allows CSRF attacks in 'usersettings.php', enabling attackers to change details, including passwords, of users, including administrators.
2
How does CVE-2018-15901 impact the affected software?
CVE-2018-15901 has a high severity rating of 8.8 and can result in attackers being able to change user details, such as passwords, of users, including administrators.
3
What version of e107 is affected by CVE-2018-15901?
e107 version 2.1.8 is affected by CVE-2018-15901.
4
How can I fix CVE-2018-15901?
To fix CVE-2018-15901, it is recommended to update e107 to a version that includes a patch for the vulnerability.
5
Where can I find more information about CVE-2018-15901?
You can find more information about CVE-2018-15901 on the following references: [link1] [link2]