EIP-2026-106823
PRE-CVEElectricks eCommerce 1.0 - Cross-Site Request Forgery (Change Admin Password)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106823. PoCs published by Nawaf Alkeraithe.
AI-analyzed exploit summary This is a CSRF exploit targeting Electricks eCommerce 1.0, allowing an attacker to change the admin password by tricking an authenticated admin into submitting a malicious form. The PoC demonstrates a simple HTML form that submits a POST request to the vulnerable endpoint.
Description
Electricks eCommerce 1.0 - Cross-Site Request Forgery (Change Admin Password)
Exploits (1)
This is a CSRF exploit targeting Electricks eCommerce 1.0, allowing an attacker to change the admin password by tricking an authenticated admin into submitting a malicious form. The PoC demonstrates a simple HTML form that submits a POST request to the vulnerable endpoint.