CVE-2018-25397

MEDIUM

PHP-SHOP 1.0 Cross-Site Request Forgery via users.php

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25397. PoCs published by Alireza Norkazemi.

AI-analyzed exploit summary This is a functional CSRF exploit for PHP-SHOP 1.0 that adds an admin user via a crafted HTML form with auto-submission. The exploit leverages lack of CSRF protection in the admin user creation endpoint.

Description

PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that automatically submits POST requests to the users.php endpoint with parameters like name, email, password, and permissions set to admin to create unauthorized admin accounts.

Exploits (1)

exploitdb WORKING POC
by Alireza Norkazemi · textwebappsphp
https://www.exploit-db.com/exploits/45636

This is a functional CSRF exploit for PHP-SHOP 1.0 that adds an admin user via a crafted HTML form with auto-submission. The exploit leverages lack of CSRF protection in the admin user creation endpoint.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: PHP-SHOP 1.0
No auth needed
Prerequisites: victim must visit the malicious page while authenticated as admin
devstral-2 · analyzed May 29, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-45636
https://www.exploit-db.com/exploits/45636
Third Party Advisory third-party-advisory
VulnCheck Advisory: PHP-SHOP 1.0 Cross-Site Request Forgery via users.php
https://www.vulncheck.com/advisories/php-shop-cross-site-request-forgery-via-users-php

Scores

CVSS v3 5.3
EPSS 0.0016
EPSS Percentile 5.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
joeyrush/PHP-SHOP master 1.0
Published May 29, 2026
Tracked Since May 29, 2026