SQL Injection Vulnerability in e107 CMS by e107 Inc.
CVE-2016-10378

7.2HIGH

Key Information:

Vendor

E107

Status
Vendor
CVE Published:
29 May 2017

What is CVE-2016-10378?

The e107 CMS version 2.1.1 contains a SQL injection vulnerability that allows remote authenticated administrators to execute arbitrary SQL commands via the 'pagelist' parameter in the e107_admin/menus.php file. This flaw is associated with the menuSaveVisibility function, posing a risk to the integrity and security of the application's database and potentially enabling unauthorized data manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.