Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-104957. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates a CSV injection vulnerability in admidio v4.2.5, where a user can inject a malicious payload into their profile's postal code field. When an admin exports user data as a CSV file, the payload executes arbitrary commands (e.g., opening the calculator) on the admin's machine.
Description
admidio v4.2.5 - CSV Injection
Exploits (1)
This exploit demonstrates a CSV injection vulnerability in admidio v4.2.5, where a user can inject a malicious payload into their profile's postal code field. When an admin exports user data as a CSV file, the payload executes arbitrary commands (e.g., opening the calculator) on the admin's machine.