CVE-2020-37217

MEDIUM

Easy2Pilot 7 Cross-Site Request Forgery via admin.php

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37217. PoCs published by indoushka.

AI-analyzed exploit summary This is a functional CSRF PoC for Easy2Pilot 7 that crafts an HTML form to add a new user via a POST request to the admin panel. The exploit leverages a lack of CSRF token validation in the application.

Description

Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the admin.php?action=add_user endpoint with POST requests containing username and password parameters to create new administrative accounts without explicit user consent.

Exploits (1)

exploitdb WORKING POC
by indoushka · textwebappsphp
https://www.exploit-db.com/exploits/48099

This is a functional CSRF PoC for Easy2Pilot 7 that crafts an HTML form to add a new user via a POST request to the admin panel. The exploit leverages a lack of CSRF token validation in the application.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Easy2Pilot 7
No auth needed
Prerequisites: Victim must be authenticated as an admin and visit the malicious HTML page
devstral-2 · analyzed May 13, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-48099
https://www.exploit-db.com/exploits/48099
Product product
Official Product Homepage
http://easy2pilot-v7.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Easy2Pilot 7 Cross-Site Request Forgery via admin.php
https://www.vulncheck.com/advisories/easy2pilot-7-cross-site-request-forgery-via-admin-php

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 3.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (2)
Easy2Pilot/Easy2Pilot 7
Easy2pilot-v7/Easy2Pilot 7
Published May 13, 2026
Tracked Since May 13, 2026