CVE-2018-11092
MEDIUMAdmin Notes 1.1 - Cross-Site Request Forgery via Clear Table Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-11092. PoCs published by 0xB9.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the MyBB Admin Notes Plugin version 1.1, allowing an attacker to remotely delete all admin notes via a crafted HTML page. The PoC uses a simple img tag to trigger the deletion without user interaction.
Description
An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in the MyBB Admin Notes Plugin version 1.1, allowing an attacker to remotely delete all admin notes via a crafted HTML page. The PoC uses a simple img tag to trigger the deletion without user interaction.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N