CVE-2015-6655
Pligg CMS 2.0.2 - Cross-Site Request Forgery via Admin User Addition
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-6655. PoCs published by Arash Khazaei.
AI-analyzed exploit summary This is a CSRF exploit for Pligg CMS 2.0.2 that allows an attacker to add an admin user by tricking an authenticated admin into submitting a malicious form. The exploit leverages a lack of CSRF protection in the admin user creation functionality.
Description
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.
Exploits (1)
This is a CSRF exploit for Pligg CMS 2.0.2 that allows an attacker to add an admin user by tricking an authenticated admin into submitting a malicious form. The exploit leverages a lack of CSRF protection in the admin user creation functionality.