EIP-2026-103920
PRE-CVEHelix Server 14.0.1.571 - Administration Interface Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103920. PoCs published by John Leitch.
AI-analyzed exploit summary This is a functional proof-of-concept for a CSRF vulnerability in Helix Server, allowing an attacker to add a new admin user by tricking a logged-in user into visiting a malicious page. The exploit leverages a crafted HTML image tag to submit an unauthorized request to the server.
Description
Helix Server 14.0.1.571 - Administration Interface Cross-Site Request Forgery
Exploits (1)
This is a functional proof-of-concept for a CSRF vulnerability in Helix Server, allowing an attacker to add a new admin user by tricking a logged-in user into visiting a malicious page. The exploit leverages a crafted HTML image tag to submit an unauthorized request to the server.