Description
e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files with embedded cross-site scripting (XSS) payloads that can execute arbitrary scripts when viewed.
References
Product
Product
https://www.exploit-db.com/exploits/50910
ExploitThird Party AdvisoryVDB Entry
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
6.4 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-13T23:15:53.260Z
2 days agoLast modified
2026-01-15T22:18:16.960Z
2 hours ago