SQL Injection Vulnerability in e107 CMS by e107 Inc.
CVE-2016-10378
7.2HIGH
What is CVE-2016-10378?
The e107 CMS version 2.1.1 contains a SQL injection vulnerability that allows remote authenticated administrators to execute arbitrary SQL commands via the 'pagelist' parameter in the e107_admin/menus.php file. This flaw is associated with the menuSaveVisibility function, posing a risk to the integrity and security of the application's database and potentially enabling unauthorized data manipulation.
