vendor:
e107 CMS
by:
Tadjmen
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: e107 CMS
Affected Version From: 2.3.0
Affected Version To: 2.3.0
Patch Exists: YES
Related CWE: CVE-2021-27885
CPE: 2.3.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2021
e107 CMS 2.3.0 – CSRF
A CSRF vulnerability was found on the e107 CMS. An attacker can change the password of any user by sending them a malicious link. The malicious link contains a code which when clicked by the user, changes the password of the user.
Mitigation:
Use a strong password policy, two-factor authentication, and a web application firewall.