Cross-Site Request Forgery in e107 Content Management System by e107inc
CVE-2017-8098
6.5MEDIUM
What is CVE-2017-8098?
e107 version 2.1.4 is susceptible to Cross-Site Request Forgery (CSRF), which allows an attacker to manipulate the system into downloading and installing plugins without proper user consent. By crafting a malicious web page, an attacker can send forged requests to the e107 platform, potentially leading to unauthorized plugin installations that compromise the security and functionality of the website.
