Description
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Portfolio Responsive Gallery SQL Injection (1.1.7)
WordPress Plugin Product list Widget for Woocommerce Cross-Site Scripting (1.0)
WordPress Plugin Candidate Application Form Arbitrary File Disclosure (1.6)
WordPress Plugin WooCommerce PDF Invoices & Packing Slips Cross-Site Request Forgery (2.2.6)