CVE-2020-37091

MEDIUM

Maian Support Helpdesk 4.3 - Unauthenticated Cross-Site Request Forgery to Add Admin

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37091. PoCs published by Besim.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Maian Support Helpdesk 4.3, allowing an attacker to add an admin account or upload arbitrary files (including PHP shells) via crafted HTML forms. The PoC includes two separate payloads: one for admin creation and another for file upload.

Description

Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system.

Exploits (1)

exploitdb WORKING POC
by Besim · textwebappsphp
https://www.exploit-db.com/exploits/48386

This exploit demonstrates a CSRF vulnerability in Maian Support Helpdesk 4.3, allowing an attacker to add an admin account or upload arbitrary files (including PHP shells) via crafted HTML forms. The PoC includes two separate payloads: one for admin creation and another for file upload.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Maian Support Helpdesk v4.3
No auth needed
Prerequisites: Victim must visit a malicious webpage while authenticated as an admin
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/48386
Various Sources product
https://www.maiansupport.com

Scores

CVSS v3 5.3
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
Maian Media/Maian Support Helpdesk 4.3
Published Feb 03, 2026
Tracked Since Feb 18, 2026