EIP-2026-105113
PRE-CVEAllomani Web Links 1.0 - Cross-Site Request Forgery (Add Admin)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105113. PoCs published by AtT4CKxT3rR0r1ST.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Request Forgery (XSRF/CSRF) vulnerability in Web Links 1.0, allowing an attacker to add an admin user by tricking an authenticated admin into submitting a malicious form. The form includes predefined values for username, password, and group_id to escalate privileges.
Description
Allomani Web Links 1.0 - Cross-Site Request Forgery (Add Admin)
Exploits (1)
This exploit demonstrates a Cross-Site Request Forgery (XSRF/CSRF) vulnerability in Web Links 1.0, allowing an attacker to add an admin user by tricking an authenticated admin into submitting a malicious form. The form includes predefined values for username, password, and group_id to escalate privileges.