EIP-2026-100243
PRE-CVEDigileave 1.2 - Cross-Site Request Forgery (Update Admin)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100243. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in Digileave 1.2, allowing an attacker to update user or admin credentials via a crafted HTML form. The PoC generates an HTML file that, when loaded by an authenticated victim, submits a malicious request to change account details.
Description
Digileave 1.2 - Cross-Site Request Forgery (Update Admin)
Exploits (1)
This exploit demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in Digileave 1.2, allowing an attacker to update user or admin credentials via a crafted HTML form. The PoC generates an HTML file that, when loaded by an authenticated victim, submits a malicious request to change account details.