CVE-2018-16381: XSS
Published Sep 5, 2018
·Updated
e107 2.1.8 has XSS via the e107admin/users.php?mode=main&action=list userloginname parameter.
Affected Software
1 affected component
e107 e107=2.1.8
Event History
Sep 5, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16381?
CVE-2018-16381 is a vulnerability in e107 2.1.8 that allows for cross-site scripting (XSS) attacks via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
2
How severe is CVE-2018-16381?
CVE-2018-16381 has a severity rating of medium, with a CVSS score of 6.1.
3
How does CVE-2018-16381 affect e107?
CVE-2018-16381 affects e107 version 2.1.8.
4
How can the XSS vulnerability in CVE-2018-16381 be exploited?
The XSS vulnerability in CVE-2018-16381 can be exploited by manipulating the user_loginname parameter in the e107_admin/users.php?mode=main&action=list URL.
5
Is there a fix for CVE-2018-16381?
To fix CVE-2018-16381, users should apply the necessary updates or patches provided by e107.