EIP-2026-104843

PRE-CVE

4Images 1.7.6-9 - Cross-Site Request Forgery / PHP Code Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104843. PoCs published by Or4nG.M4N.

AI-analyzed exploit summary This exploit leverages a CSRF vulnerability in 4images 1.7.6 to inject a PHP backdoor into a template file, allowing remote command execution. The script automates the creation of an HTML form that submits malicious template content to the admin panel.

Description

4Images 1.7.6-9 - Cross-Site Request Forgery / PHP Code Injection

Exploits (1)

exploitdb WORKING POC
by Or4nG.M4N · perlwebappsphp
https://www.exploit-db.com/exploits/18429

This exploit leverages a CSRF vulnerability in 4images 1.7.6 to inject a PHP backdoor into a template file, allowing remote command execution. The script automates the creation of an HTML form that submits malicious template content to the admin panel.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: 4images 1.7.6 > 9
Auth required
Prerequisites: Admin access to the target application via CSRF · Victim must visit the crafted HTML page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026