CVE-2012-5326

iSupport 1.x - Cross-Site Request Forgery via Administrator Account Addition

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5326. PoCs published by Or4nG.M4N.

AI-analyzed exploit summary This exploit leverages an HTML injection vulnerability in iSupport v1.x to add an admin user by crafting a malicious form that submits to the admin function. It generates an HTML file and an iframe to trigger the payload.

Description

Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.

Exploits (1)

exploitdb WORKING POC
by Or4nG.M4N · perlwebappsphp
https://www.exploit-db.com/exploits/18404

This exploit leverages an HTML injection vulnerability in iSupport v1.x to add an admin user by crafting a malicious form that submits to the admin function. It generates an HTML file and an iframe to trigger the payload.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: iSupport v1.x
No auth needed
Prerequisites: Access to upload a file to a web server · Victim interaction to trigger the payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18404
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72611

Scores

EPSS 0.0036
EPSS Percentile 58.6%

Details

CWE
CWE-352
Status published
Products (4)
idevspot/isupport 1.0
idevspot/isupport 1.02
idevspot/isupport 1.06
idevspot/isupport 1.8
Published Oct 08, 2012
Tracked Since Feb 18, 2026