Cross-Site Request Forgery in e107 by e107 Inc. Allows User Deletion
CVE-2018-11127
6.5MEDIUM
What is CVE-2018-11127?
The e107 CMS version 2.1.7 is vulnerable to Cross-Site Request Forgery (CSRF), allowing authorized attackers to delete arbitrary users without their consent. This security flaw can jeopardize the integrity of user accounts and overall site security. Implement proper protections against CSRF attacks to safeguard your e107 installation.
