CVE-2020-37217
MEDIUMEasy2Pilot 7 Cross-Site Request Forgery via admin.php
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37217. PoCs published by indoushka.
AI-analyzed exploit summary This is a functional CSRF PoC for Easy2Pilot 7 that crafts an HTML form to add a new user via a POST request to the admin panel. The exploit leverages a lack of CSRF token validation in the application.
Description
Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the admin.php?action=add_user endpoint with POST requests containing username and password parameters to create new administrative accounts without explicit user consent.
Exploits (1)
This is a functional CSRF PoC for Easy2Pilot 7 that crafts an HTML form to add a new user via a POST request to the admin panel. The exploit leverages a lack of CSRF token validation in the application.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N