CVE-2015-5075
X2Engine X2CRM < 5.0.9 - Cross-Site Request Forgery via User Creation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-5075. PoCs published by Portcullis.
AI-analyzed exploit summary This is a CSRF exploit for CVE-2015-5075, which allows an attacker to force the creation of a new administrative account in X2Engine. The exploit is delivered via an HTML form that submits a POST request to the vulnerable endpoint.
Description
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators for requests that create an administrative account via a crafted request to index.php/users/create.
Exploits (1)
This is a CSRF exploit for CVE-2015-5075, which allows an attacker to force the creation of a new administrative account in X2Engine. The exploit is delivered via an HTML form that submits a POST request to the vulnerable endpoint.