Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-108022. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in iTop that allows remote code execution by injecting malicious PHP code into the configuration file. The PoC includes a form that, when submitted by an authenticated administrator, injects a PHP payload enabling arbitrary command execution via a GET parameter.
Description
iTop 2.2.1 - Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in iTop that allows remote code execution by injecting malicious PHP code into the configuration file. The PoC includes a form that, when submitted by an authenticated administrator, injects a PHP payload enabling arbitrary command execution via a GET parameter.