EIP-2026-104843
PRE-CVE4Images 1.7.6-9 - Cross-Site Request Forgery / PHP Code Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104843. PoCs published by Or4nG.M4N.
AI-analyzed exploit summary This exploit leverages a CSRF vulnerability in 4images 1.7.6 to inject a PHP backdoor into a template file, allowing remote command execution. The script automates the creation of an HTML form that submits malicious template content to the admin panel.
Description
4Images 1.7.6-9 - Cross-Site Request Forgery / PHP Code Injection
Exploits (1)
exploitdb
WORKING POC
by Or4nG.M4N · perlwebappsphp
https://www.exploit-db.com/exploits/18429
This exploit leverages a CSRF vulnerability in 4images 1.7.6 to inject a PHP backdoor into a template file, allowing remote command execution. The script automates the creation of an HTML form that submits malicious template content to the admin panel.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
4images 1.7.6 > 9
Auth required
Prerequisites:
Admin access to the target application via CSRF · Victim must visit the crafted HTML page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026