CVE-2018-17081

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
26/09/2018
Last modified:
26/11/2018

Description

e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:e107:e107:2.1.9:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools