EIP-2026-106998
PRE-CVEEz News Manager / Pro - Cross-Site Request Forgery (Change Admin Password)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106998. PoCs published by Milos Zivanovic.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Ez News Manager and Ez News Manager Pro, allowing an attacker to change the admin password via a crafted HTML form. The PoC is functional and directly targets the password change endpoint without requiring authentication.
Description
Ez News Manager / Pro - Cross-Site Request Forgery (Change Admin Password)
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Ez News Manager and Ez News Manager Pro, allowing an attacker to change the admin password via a crafted HTML form. The PoC is functional and directly targets the password change endpoint without requiring authentication.