Cross-Site Request Forgery Vulnerability in e107 CMS
CVE-2014-9459

Currently unrated

Key Information:

Vendor

E107

Status
Vendor
CVE Published:
2 January 2015

What is CVE-2014-9459?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the AdminObserver function of the e107 CMS, specifically in the users.php file. This flaw allows remote attackers to exploit the id parameter within an admin action, potentially compromising the authentication of administrators. By doing so, attackers can execute unauthorized actions such as adding new users to the administrator group, thereby increasing the risk of further exploitation or unauthorized access to sensitive site functionalities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.