CVE-2017-16244

HIGH

OctoberCMS < 1.0.427 - Cross-Site Request Forgery via _handler Postback Variable

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-16244. PoCs published by Zain Sabahat.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in OctoberCMS 1.0.426, allowing an attacker to bypass CSRF protections by using the '_handler' parameter to take over an admin account.

Description

Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable.

Exploits (1)

exploitdb WORKING POC
by Zain Sabahat · textwebappsphp
https://www.exploit-db.com/exploits/43106

This exploit demonstrates a CSRF vulnerability in OctoberCMS 1.0.426, allowing an attacker to bypass CSRF protections by using the '_handler' parameter to take over an admin account.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: OctoberCMS 1.0.426
No auth needed
Prerequisites: Victim must be authenticated as an admin and visit the malicious HTML page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43106/

Scores

CVSS v3 8.8
EPSS 0.0040
EPSS Percentile 61.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (2)
october/october 0 - 1.0.427Packagist
octobercms/october 1.0.426
Published Nov 01, 2017
Tracked Since Feb 18, 2026