Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote malicious users to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
e107 e107 1.0.1 |