First published: Wed Sep 26 2018(Updated: )
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E107 E107 | =2.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17081 is a vulnerability in e107 2.1.9 that allows CSRF attacks via the e107_admin/wmessage.php file.
CVE-2018-17081 affects e107 version 2.1.9.
CVE-2018-17081 has a severity rating of 4.3 (Medium).
An attacker can exploit CVE-2018-17081 by performing a Cross-Site Request Forgery attack via the e107_admin/wmessage.php file.
At the moment, there is no known fix or patch available for CVE-2018-17081. It is recommended to follow the provided reference for any updates or official patches.