Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-107518. PoCs published by Kacper.
AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in Guestbara <= 1.2, allowing an attacker to change the administrative password via a crafted POST request to the configuration.php endpoint. The HTML form submits directly to the vulnerable endpoint without requiring prior authentication.
Description
Guesbara 1.2 - Administrator Password Change
Exploits (1)
This exploit leverages an authentication bypass vulnerability in Guestbara <= 1.2, allowing an attacker to change the administrative password via a crafted POST request to the configuration.php endpoint. The HTML form submits directly to the vulnerable endpoint without requiring prior authentication.