CVE-2010-3024

DiamondList 0.1.6 - Cross-Site Request Forgery in User Update Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-3024. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in DiamondList 0.1.6, allowing an attacker to submit a crafted form to update user details, including passwords, without proper request verification. The PoC includes a hidden form with JavaScript auto-submission to trigger the attack.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · htmlwebappsphp
https://www.exploit-db.com/exploits/14565

This exploit demonstrates a CSRF vulnerability in DiamondList 0.1.6, allowing an attacker to submit a crafted form to update user details, including passwords, without proper request verification. The PoC includes a hidden form with JavaScript auto-submission to trigger the attack.

Classification
Working Poc 100%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: DiamondList 0.1.6 and prior versions
No auth needed
Prerequisites: Victim must be authenticated in the target application · Attacker must trick victim into visiting a malicious page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/66918
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=128104130309426&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/60937
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40873
Vendor Advisory x_refsource_confirm
http://dev.hulihanapplications.com/issues/show/212
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/14565
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.org/1008-exploits/diamondlist-xssxsrf.txt

Scores

EPSS 0.0143
EPSS Percentile 69.6%

Details

CWE
CWE-352
Status published
Products (1)
hulihanapplications/diamondlist 0.1.6
Published Aug 16, 2010
Tracked Since Feb 18, 2026