EIP-2026-105293
PRE-CVEATutor 2.2.2 - Cross-Site Request Forgery (Add New Course)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105293. PoCs published by Saravana Kumar.
AI-analyzed exploit summary This is a functional CSRF PoC for ATutor 2.2.2 that demonstrates how an attacker can trick a victim into submitting a crafted POST request to create a new course without their consent. The exploit uses JavaScript to send a multipart/form-data request to the vulnerable endpoint.
Description
ATutor 2.2.2 - Cross-Site Request Forgery (Add New Course)
Exploits (1)
This is a functional CSRF PoC for ATutor 2.2.2 that demonstrates how an attacker can trick a victim into submitting a crafted POST request to create a new course without their consent. The exploit uses JavaScript to send a multipart/form-data request to the vulnerable endpoint.