PT-2026-43266 · E107 · E107

Longnv719

·

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-43934

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions e107 versions prior to 2.3.4
Description e107 is a content management system (CMS) containing a broken access control issue. An authenticated user can edit comments posted by other users due to inadequate server-side access control validation. The application relies solely on a predictable identifier in the request to determine the comment to be edited, failing to verify if the requesting user owns the comment.
Recommendations Update to version 2.3.4.

Exploit

Fix

Improper Access Control

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-43934

Affected Products

E107