SQL Injection Vulnerability in e107 Product by e107inc
CVE-2026-72599
9.8CRITICAL
What is CVE-2026-72599?
An SQL injection flaw in e107 version 2.4.0 permits remote attackers, without authentication, to execute arbitrary SQL commands through the news item page ID parameter. This vulnerability arises from improper input handling, where user-supplied data is concatenated into an SQL WHERE clause without adequate escaping. An attacker can leverage this vulnerability to manipulate database queries, enabling unauthorized access to read, alter, or delete data, including sensitive information like administrator credentials.
Affected Version(s)
e107 0 <= 2.4.0
