Description
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
Remediation
References
Related Vulnerabilities
WordPress Plugin iThemes Security (formerly Better WP Security) Cross-Site Scripting (5.3.4)
Squid Improper Handling of Exceptional Conditions Vulnerability (CVE-2023-5824)
MySQL CVE-2021-2122 Vulnerability (CVE-2021-2122)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8707)
Apache Tomcat Improper Authentication Vulnerability (CVE-2011-5063)