CVE-2018-15901

HIGH

e107 2.1.8 - Cross-Site Request Forgery in usersettings.php

Title source: llm
STIX 2.1

Description

e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.

Scores

CVSS v3 8.8
EPSS 0.0056
EPSS Percentile 42.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
e107/e107 2.1.8
Published Aug 28, 2018
Tracked Since Feb 18, 2026