PT-2026-43269 · E107 · E107

·

CVE-2026-46620

·

Published

2026-05-26

·

Updated

2026-05-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions e107 versions prior to 2.3.5
Description e107 is a content management system (CMS) that fails to properly enforce Cross-Site Request Forgery (CSRF) token validation on comment moderation actions. The issue occurs within the session handler::check() function, which only validates the CSRF token if it is present in the request. If the token is completely missing, the validation check is skipped, allowing state-changing requests to be processed without authentication. This affects the 'comment.php' moderation endpoints.
Recommendations Update to version 2.3.5.

Exploit

Fix

Improper Authorization

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46620
GHSA-M4HH-M278-JWG5

Affected Products

E107