CVE-2018-17081: CSRF
Published Sep 26, 2018
·Updated
e107 2.1.9 allows CSRF via e107admin/wmessage.php?mode=&action=inline&ajaxused=1&id= for changing the title of an arbitrary page.
Affected Software
1 affected component
e107 e107=2.1.9
Event History
Sep 26, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-17081?
CVE-2018-17081 is a vulnerability in e107 2.1.9 that allows CSRF attacks via the e107_admin/wmessage.php file.
2
How does CVE-2018-17081 affect e107?
CVE-2018-17081 affects e107 version 2.1.9.
3
What is the severity of CVE-2018-17081?
CVE-2018-17081 has a severity rating of 4.3 (Medium).
4
How can an attacker exploit CVE-2018-17081?
An attacker can exploit CVE-2018-17081 by performing a Cross-Site Request Forgery attack via the e107_admin/wmessage.php file.
5
Is there a fix available for CVE-2018-17081?
At the moment, there is no known fix or patch available for CVE-2018-17081. It is recommended to follow the provided reference for any updates or official patches.