CVE-2011-0535

Zikula Application Framework < 1.2.5 - Cross-Site Request Forgery via Users Module

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-0535. PoCs published by Aung Khant.

AI-analyzed exploit summary This document provides a detailed technical analysis of a CSRF vulnerability in Zikula CMS 1.2.4 and earlier versions, including a proof-of-concept request that demonstrates how an attacker could escalate a normal user to an administrator. The writeup includes background, vulnerability description, affected versions, and a solution.

Description

Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change account privileges via an edit access_permissions action to index.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Aung Khant · textwebappsphp
https://www.exploit-db.com/exploits/16097

This document provides a detailed technical analysis of a CSRF vulnerability in Zikula CMS 1.2.4 and earlier versions, including a proof-of-concept request that demonstrates how an attacker could escalate a normal user to an administrator. The writeup includes background, vulnerability description, affected versions, and a solution.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Zikula CMS <= 1.2.4
Auth required
Prerequisites: Victim must be authenticated in Zikula CMS · Attacker must trick victim into visiting a crafted URL
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/02/03/1
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/70751
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43114
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8067
Exploit mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/02/01/1
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2011/Feb/0

Scores

EPSS 0.0143
EPSS Percentile 69.6%

Details

CWE
CWE-352
Status published
Products (5)
zikula/zikula_application_framework 1.1.2
zikula/zikula_application_framework 1.2.1
zikula/zikula_application_framework 1.2.2
zikula/zikula_application_framework 1.2.3
zikula/zikula_application_framework < 1.2.4
Published Feb 08, 2011
Tracked Since Feb 18, 2026