VYPR
Unrated severityNVD Advisory· Published Apr 20, 2010· Updated Apr 29, 2026

CVE-2010-0997

CVE-2010-0997

Description

Cross-site scripting (XSS) vulnerability in 107_plugins/content/content_manager.php in the Content Management plugin in e107 before 0.7.20, when the personal content manager is enabled, allows user-assisted remote authenticated users to inject arbitrary web script or HTML via the content_heading parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting in e107 Content Management plugin allows authenticated users to inject arbitrary web script via content_heading parameter.

Vulnerability

The Content Management plugin in e107 before version 0.7.20 contains a cross-site scripting (XSS) vulnerability in the file 107_plugins/content/content_manager.php. The vulnerability is triggered when the personal content manager is enabled and an authenticated user supplies a crafted content_heading parameter. The affected versions are all e107 releases prior to 0.7.20 [1][2].

Exploitation

An attacker must be an authenticated user with access to the personal content manager. The attacker can inject arbitrary web script or HTML into the content_heading parameter. The attack is user-assisted, meaning that the victim must view the manipulated content (e.g., by visiting a page or clicking a link) for the script to execute [1].

Impact

Successful exploitation allows the attacker to execute arbitrary script or HTML in the context of the victim's browser. This can lead to session hijacking, defacement, or other client-side attacks. The attacker gains the ability to impersonate the victim or steal sensitive information [1].

Mitigation

The vulnerability is fixed in e107 version 0.7.20, released on an unspecified date. Users should upgrade to this version or later [2]. If upgrading is not immediately possible, the personal content manager feature should be disabled to mitigate the risk [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.