CVE-2017-8098: e107

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.

Affected products

  • e107 e107: version 2.1.4 only

Published 2017-04-24. Last modified 2026-06-17.