CVE-2021-27885
HIGHe107 < 2.3.0 - Cross-Site Request Forgery via usersettings.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-27885. PoCs published by Tadjmen.
AI-analyzed exploit summary This is a CSRF exploit for e107 CMS 2.3.0 that allows an attacker to change the admin password by tricking a victim into clicking a malicious link. The PoC includes an HTML form that submits a crafted POST request to the usersettings.php endpoint.
Description
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
Exploits (1)
exploitdb
WORKING POC
by Tadjmen · textwebappsphp
https://www.exploit-db.com/exploits/49614
This is a CSRF exploit for e107 CMS 2.3.0 that allows an attacker to change the admin password by tricking a victim into clicking a malicious link. The PoC includes an HTML form that submits a crafted POST request to the usersettings.php endpoint.
Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
e107 CMS 2.3.0
No auth needed
Prerequisites:
Victim must be authenticated as admin · Victim must click the malicious link
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/e107inc/e107/releases
Patch, Third Party Advisory x_refsource_misc
https://github.com/e107inc/e107/commit/d9efdb9b5f424b4996c276e754a380a5e251f472
Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/161651/e107-CMS-2.3.0-Cross-Site-Request-Forgery.html
Scores
CVSS v3
8.8
EPSS
0.0321
EPSS Percentile
86.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (1)
e107/e107
< 2.3.0
Published
Mar 02, 2021
Tracked Since
Feb 18, 2026