Description
e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "Media Manager" on the administrator screen. This vulnerability is fixed in 2.3.4.
Problem types
CWE-918: Server-Side Request Forgery (SSRF)
Product status
References
github.com/...c/e107/security/advisories/GHSA-92fr-7h4f-22pp
github.com/...c/e107/security/advisories/GHSA-92fr-7h4f-22pp
github.com/e107inc/e107/commit/40b2d111
github.com/e107inc/e107/commit/5f98cc9f