CVE-2013-4881

BigTree CMS < 4.0 - Cross-Site Request Forgery via User Creation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-4881.

AI-analyzed exploit summary The provided exploit code includes functional PoC examples for SQL injection, CSRF, and XSS vulnerabilities in BigTree CMS 4.0 RC2. The SQLi PoC demonstrates arbitrary SQL command execution, while the CSRF exploit creates an admin user, and the XSS example executes arbitrary JavaScript.

Description

Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create an administrative user via an add user action to index.php.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/27431

The provided exploit code includes functional PoC examples for SQL injection, CSRF, and XSS vulnerabilities in BigTree CMS 4.0 RC2. The SQLi PoC demonstrates arbitrary SQL command execution, while the CSRF exploit creates an admin user, and the XSS example executes arbitrary JavaScript.

Classification
Working Poc 90%
Attack Type
Sqli | Xss | Csrf
Complexity
Trivial
Reliability
Reliable
Target: BigTree CMS 4.0 RC2
No auth needed
Prerequisites: Access to the target application
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory x_refsource_misc
https://www.htbridge.com/advisory/HTB23165
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/96009
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/86286
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-08/0039.html

Scores

EPSS 0.0220
EPSS Percentile 80.1%

Details

CWE
CWE-352
Status published
Products (2)
bigtreecms/bigtree_cms 4.0 b1 (8 CPE variants)
bigtreecms/bigtree_cms < 4.0
Published Aug 19, 2013
Tracked Since Feb 18, 2026