Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-12739. PoCs published by bay0net.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in BEESCMS V4.0, allowing an attacker to add an arbitrary administrator account via a crafted HTML form. The PoC submits a POST request with hidden form fields to create a new admin user without requiring prior authentication.
Description
In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in BEESCMS V4.0, allowing an attacker to add an arbitrary administrator account via a crafted HTML form. The PoC submits a POST request with hidden form fields to create a new admin user without requiring prior authentication.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H