Cross-Site Request Forgery Vulnerability in e107 by e107.org
CVE-2018-15901
8.8HIGH
What is CVE-2018-15901?
The e107 content management system version 2.1.8 is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability found in the 'usersettings.php' file. This security flaw allows attackers to manipulate user settings without their consent, enabling unauthorized changes to account details, including the modification of passwords for all users, even those with admin privileges. This can lead to significant data breaches and compromise the security of user accounts.
