Description
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
Remediation
References
Related Vulnerabilities
Jenkins Resource Management Errors Vulnerability (CVE-2014-3661)
MySQL CVE-2020-2660 Vulnerability (CVE-2020-2660)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-25763)
Oracle Database Server CVE-2006-5339 Vulnerability (CVE-2006-5339)
WordPress Plugin Rotating Testimonial Cross-Site Scripting (1.1)