CVE-2017-15735
HIGHphpmyfaq < 2.9.8 - Cross-Site Request Forgery for Glossary Modification
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-15735. PoCs published by CodeSecLab.
AI-analyzed exploit summary This is a functional CSRF PoC for phpMyFAQ 2.9.8, demonstrating how an attacker can trick an authenticated admin into submitting a malicious glossary update via an auto-submitting HTML form. The exploit leverages the lack of CSRF token validation in the target endpoint.
Description
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
Exploits (1)
This is a functional CSRF PoC for phpMyFAQ 2.9.8, demonstrating how an attacker can trick an authenticated admin into submitting a malicious glossary update via an auto-submitting HTML form. The exploit leverages the lack of CSRF token validation in the target endpoint.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H