e107 CMS
cpe:2.3:a:e107:e107_cms:*:*:*:*:*:*:*
- 3.2.1
An upload restriction bypass vulnerability has been identified in e107 CMS version 3.2.1. This vulnerability allows authenticated administrators to upload malicious SVG files through the media manager. Exploitation of this vulnerability involves embedding cross-site scripting (XSS) payloads within the SVG files, which can execute arbitrary scripts when the files are viewed.
Exploitation of this vulnerability leads to stored cross-site scripting, where uploaded SVG files execute scripts when accessed.
To reproduce this vulnerability, an authenticated administrator can upload an SVG file containing an XSS payload through the media manager. The uploaded file can then be accessed, triggering the execution of the embedded script.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.