Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dhananjay Bajaj

#30711of 56,330
8.8Total CVSS
Vulnerabilities · 1
PT-2018-13280
8.8
2018-08-28
E107 · E107 · CVE-2018-15901
**Name of the Vulnerable Software and Affected Versions** e107 version 2.1.8 **Description** The issue allows for Cross-Site Request Forgery (CSRF) attacks in the 'usersettings.php' file, enabling an attacker to change user details, including passwords, for all users, including administrators. **Recommendations** For e107 version 2.1.8, consider implementing CSRF protection mechanisms, such as tokens, to prevent unauthorized changes to user settings, including passwords, until a patch is available. As a temporary workaround, restrict access to the 'usersettings.php' file to minimize the risk of exploitation.