First published: Tue Aug 01 2023(Updated: )
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E107 E107 | =2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36121 is a Cross Site Scripting vulnerability in e107 v.2.3.2.
CVE-2023-36121 allows a remote attacker to execute arbitrary code via the description function in the SEO project in e107 v.2.3.2.
CVE-2023-36121 has a severity rating of medium with a CVSS score of 5.4.
To fix CVE-2023-36121, it is recommended to update e107 to a version that includes a patch for this vulnerability.
You can find more information about CVE-2023-36121 at the following references: [Link 1](https://www.exploit-db.com/exploits/51449), [Link 2](https://www.chtsecurity.com/news/6c6675d4-3254-46ce-a16d-26523ff80540), [Link 3](https://www.chtsecurity.com/news/0a4743a5-491e-4685-95ee-df8316ab5284).