CVE-2018-7176
HIGHFrontAccounting 2.4.3 - Cross-Site Request Forgery via User Permissions Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-7176. PoCs published by Samrat Das.
AI-analyzed exploit summary This is a CSRF exploit for Front Accounting ERP 2.4.3 that creates a new admin user when an authenticated admin visits a crafted HTML page. The exploit leverages the lack of anti-CSRF tokens in the application.
Description
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).
Exploits (1)
exploitdb
WORKING POC
by Samrat Das · htmlwebappsphp
https://www.exploit-db.com/exploits/44137
This is a CSRF exploit for Front Accounting ERP 2.4.3 that creates a new admin user when an authenticated admin visits a crafted HTML page. The exploit leverages the lack of anti-CSRF tokens in the application.
Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
Front Accounting ERP 2.4.3
Auth required
Prerequisites:
Authenticated admin session · Victim must visit the crafted HTML page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/44137/
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://securitywarrior9.blogspot.in/2018/02/cross-site-request-forgery-front.html
Scores
CVSS v3
8.8
EPSS
0.0018
EPSS Percentile
39.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (1)
frontaccounting/frontaccounting
2.4.3
Published
Feb 16, 2018
Tracked Since
Feb 18, 2026