CVE-2012-1498

Nikola Posa Webfoliocms1.0.2 - CSRF

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-1498. PoCs published by Ivano Binetti.

AI-analyzed exploit summary This exploit demonstrates CSRF vulnerabilities in WebfolioCMS <= 1.1.4, allowing an attacker to add an administrator account or modify web pages via crafted HTML forms. The PoC includes two separate forms for adding an admin and modifying a page, both auto-submitted via JavaScript.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2) modify a web page via a save action to admin/pages/edit/web_page_name.

Exploits (1)

exploitdb WORKING POC
by Ivano Binetti · textwebappsphp
https://www.exploit-db.com/exploits/18536

This exploit demonstrates CSRF vulnerabilities in WebfolioCMS <= 1.1.4, allowing an attacker to add an administrator account or modify web pages via crafted HTML forms. The PoC includes two separate forms for adding an admin and modifying a page, both auto-submitted via JavaScript.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WebfolioCMS <= 1.1.4
No auth needed
Prerequisites: Victim must be authenticated and visit a malicious page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/79658
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18536
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52218
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48190
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/73575

Scores

EPSS 0.0121
EPSS Percentile 64.4%

Details

CWE
CWE-352
Status published
Products (13)
nikola_posa/webfoliocms1.0.2
nikola_posa/webfoliocms1.0.3
nikola_posa/webfoliocms1.0.4
nikola_posa/webfoliocms1.0.5
nikola_posa/webfoliocms1.0.6
nikola_posa/webfoliocms1.0.7
nikola_posa/webfoliocms1.0.8
nikola_posa/webfoliocms1.0.9
nikola_posa/webfoliocms1.1.0
nikola_posa/webfoliocms1.1.1
... and 3 more
Published Mar 19, 2012
Tracked Since Feb 18, 2026