Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-104911. PoCs published by Pablo Milano.
AI-analyzed exploit summary The advisory describes a Cross-Site Request Forgery (CSRF) vulnerability in Achievo 1.4.3, where an attacker can trick a logged-in user into deleting projects or activities by manipulating the 'confirm' parameter in the URL. The proof of concept demonstrates the exploit via crafted URLs.
Description
Achievo 1.4.3 - Cross-Site Request Forgery
Exploits (1)
The advisory describes a Cross-Site Request Forgery (CSRF) vulnerability in Achievo 1.4.3, where an attacker can trick a logged-in user into deleting projects or activities by manipulating the 'confirm' parameter in the URL. The proof of concept demonstrates the exploit via crafted URLs.