{"id":"CVE-2016-10378","details":"e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.","modified":"2026-04-11T19:41:17.994562Z","published":"2017-05-29T19:29:00.250Z","references":[{"type":"EVIDENCE","url":"http://code610.blogspot.com/2016/09/sql-injection-in-latest-e107-cms.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/e107inc/e107","events":[{"introduced":"0"},{"last_affected":"5f005b50b2ab5aa3afa69a37e33f4b2f86f8e4ea"}],"database_specific":{"cpe":"cpe:2.3:a:e107:e107:2.1.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.1.1"}],"source":"CPE_FIELD"}}],"versions":["v2.0-beta1","v2.0alpha","v2.1.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10378.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}