CVE-2010-5084

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
14/02/2012
Last modified:
11/04/2025

Description

The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which allows remote attackers to hijack the authentication of administrators for requests that add new users via e107_admin/users.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:e107:e107:*:*:*:*:*:*:*:* 0.7.22 (including)
cpe:2.3:a:e107:e107:0.6_10:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_11:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_12:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_13:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_14:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_15:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.6_15a:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.3:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.4:*:*:*:*:*:*:*
cpe:2.3:a:e107:e107:0.7.5:*:*:*:*:*:*:*