An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
e107
Vendor: e107
Security Vulnerability Index
Page 2 / 113e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without an HMAC.
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.
e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type.
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
e107 2.1.7 has CSRF resulting in arbitrary user deletion.
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.