CVE-2017-8098

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
24/04/2017
Last modified:
20/04/2025

Description

e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:e107:e107:2.1.4:*:*:*:*:*:*:*