CVE-2010-4750

BLOG:CMS 4.2.1.e - Cross-Site Request Forgery in admin/libs/ADMIN.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4750. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in BLOG:CMS 4.2.1.e, including CSRF and XSS. It provides PoC code for CSRF attacks to modify user settings and XSS via unsanitized input in 'body', 'amount', and 'action' variables.

Description

Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administrators.

Exploits (1)

exploitdb WORKING POC
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/15743

The exploit demonstrates multiple vulnerabilities in BLOG:CMS 4.2.1.e, including CSRF and XSS. It provides PoC code for CSRF attacks to modify user settings and XSS via unsanitized input in 'body', 'amount', and 'action' variables.

Classification
Working Poc 100%
Attack Type
Xss | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: BLOG:CMS 4.2.1.e
No auth needed
Prerequisites: Victim must visit a malicious page or submit crafted input
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15743
Patch x_refsource_misc
http://blogcms.com/
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8112

Scores

EPSS 0.0102
EPSS Percentile 58.9%

Details

CWE
CWE-352
Status published
Products (1)
blogcms/blog\ cms 4.2.1.e
Published Mar 01, 2011
Tracked Since Feb 18, 2026