CVE-2011-4921: e107
Medium severity, CVSS 5.1. EPSS: 1% chance of exploitation in the next 30 days.
SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrary SQL commands via the username parameter.
Affected products
- e107 e107: version 0.7.26 only
Published 2012-01-04. Last modified 2026-06-16.