CVE-2018-17996
MEDIUMLayerBB < 1.1.3 - Cross-Site Request Forgery via Admin and Moderator Endpoints
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-17996. PoCs published by 0xB9.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in LayerBB 1.1.2, allowing an attacker to create an admin user via a crafted HTML form. The PoC submits a POST request to the admin user creation endpoint with predefined credentials and admin privileges.
Description
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in LayerBB 1.1.2, allowing an attacker to create an admin user via a crafted HTML form. The PoC submits a POST request to the admin user creation endpoint with predefined credentials and admin privileges.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N