Description
The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which allows remote attackers to hijack the authentication of administrators for requests that add new users via e107_admin/users.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Review Unspecified Vulnerability (5.2.1)
WordPress Plugin Integration for Contact Form 7 and Mailchimp Cross-Site Scripting (1.0.9)
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2022-29224)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0061)