Description
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
Remediation
References
Related Vulnerabilities
Jetty Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-6762)
Oracle Database Server Other Vulnerability (CVE-2002-0856)
WordPress Plugin WP Survey And Quiz Tool 'action' Parameter Cross-Site Scripting (1.2.1)
WordPress Plugin Admin Bar User Switching Cross-Site Scripting (1.0.4)