Description
The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which allows remote attackers to hijack the authentication of administrators for requests that add new users via e107_admin/users.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin BadgeOS SQL Injection (3.7.1.2)
WordPress Plugin Post Grid, List for WordPress-Content Views Cross-Site Scripting (1.9.0)
MySQL CVE-2012-0496 Vulnerability (CVE-2012-0496)
Apache HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-40898)
WordPress Plugin SEO-Dashboard by gutewebsites.de Cross-Site Scripting (1.2.5)