CVE-2012-5005

VR GPub 4.0 - Cross-Site Request Forgery in Admin Options

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5005. PoCs published by Cyber-Crystal.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in VR GPub 4.0, allowing an attacker to add an admin account by tricking a logged-in admin into submitting a malicious form. The PoC includes a pre-filled HTML form that submits credentials to the target application.

Description

Cross-site request forgery (CSRF) vulnerability in admin/admin_options.php in VR GPub 4.0 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an add action.

Exploits (1)

exploitdb WORKING POC
by Cyber-Crystal · htmlwebappsphp
https://www.exploit-db.com/exploits/18418

This exploit demonstrates a CSRF vulnerability in VR GPub 4.0, allowing an attacker to add an admin account by tricking a logged-in admin into submitting a malicious form. The PoC includes a pre-filled HTML form that submits credentials to the target application.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: VR GPub 4.0
Auth required
Prerequisites: Victim must be authenticated as an admin in VR GPub · Victim must visit the malicious HTML page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72745
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18418
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47729

Scores

EPSS 0.0107
EPSS Percentile 60.4%

Details

CWE
CWE-352
Status published
Products (1)
frankdeveloper/vr_gpub 4.0
Published Sep 19, 2012
Tracked Since Feb 18, 2026