Description
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Ahmet Agar / 0x97 · textwebappsphp
https://www.exploit-db.com/exploits/35679
References (3)
Core 3
Core References
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/35679
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99627
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/show/osvdb/116692
Scores
EPSS
0.0412
EPSS Percentile
88.7%
Details
CWE
CWE-79
Status
published
Products (1)
e107/e107
2.0.0
Published
Jan 16, 2015
Tracked Since
Feb 18, 2026