CVE-2014-4718

Lunar CMS < 3.3 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-4718. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates CSRF and stored XSS vulnerabilities in Lunar CMS 3.3. It includes PoC HTML forms to add an admin user and inject malicious scripts via the Contact Form module.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administrators for requests that (1) add Super users via a request to admin/user_create.php or conduct cross-site scripting (XSS) attacks via the (2) email or (3) subject parameter in contact_form.ext.php to admin/extensions.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/33830

This exploit demonstrates CSRF and stored XSS vulnerabilities in Lunar CMS 3.3. It includes PoC HTML forms to add an admin user and inject malicious scripts via the Contact Form module.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Lunar CMS 3.3
Auth required
Prerequisites: Victim must be authenticated as an admin · Victim must visit a malicious page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68153
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/108351
Patch x_refsource_confirm
http://lunarcms.com/Get.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59411
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/33830
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/108350

Scores

EPSS 0.0231
EPSS Percentile 81.1%

Details

CWE
CWE-352
Status published
Products (4)
lunarcms/lunar_cms 3.1
lunarcms/lunar_cms 3.2
lunarcms/lunar_cms 3.3
lunarcms/lunar_cms < 3.3
Published Jul 03, 2014
Tracked Since Feb 18, 2026