CVE-2010-2039

gpEasy CMS <= 1.6.2 - Cross-Site Request Forgery via Admin_Users Action

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2010-2039. PoCs published by Giuseppe 'giudinvx' D'Inverno, RajeshTiwiva.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in gpEasy <= 1.6.1, allowing an attacker to create an admin user by tricking an authenticated admin into submitting a malicious form.

Description

Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Giuseppe 'giudinvx' D'Inverno · htmlwebappsphp
https://www.exploit-db.com/exploits/12441

This exploit demonstrates a CSRF vulnerability in gpEasy <= 1.6.1, allowing an attacker to create an admin user by tricking an authenticated admin into submitting a malicious form.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: gpEasy <= 1.6.1
Auth required
Prerequisites: Victim must be authenticated as an admin · Victim must be tricked into submitting the form
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by RajeshTiwiva · poc
https://github.com/RajeshTiwiva/CVE-2010-2039

This PoC exploits an authentication bypass vulnerability in the target software by sending a crafted POST request to create a new admin user without proper authorization. The exploit leverages a flawed user creation mechanism in the Admin_Users endpoint.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Unknown (likely a CMS or web application with Admin_Users endpoint)
No auth needed
Prerequisites: Access to the target URL · Network connectivity to the target
devstral-2 · analyzed May 19, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/58214
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1030
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39643
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/12441
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64130

Scores

EPSS 0.0114
EPSS Percentile 62.5%

Details

CWE
CWE-352
Status published
Products (5)
gpeasy/gpeasy_cms 1.5 (4 CPE variants)
gpeasy/gpeasy_cms 1.6 (6 CPE variants)
gpeasy/gpeasy_cms 1.6.1
gpeasy/gpeasy_cms 1.6.3
gpeasy/gpeasy_cms < 1.6.2
Published May 25, 2010
Tracked Since Feb 18, 2026