CVE-2018-15901

HIGH

E107 - CSRF

Title source: rule
STIX 2.1

Description

e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.

Scores

CVSS v3 8.8
EPSS 0.0013
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
e107/e107 2.1.8
Published Aug 28, 2018
Tracked Since Feb 18, 2026