EIP-2026-109174
PRE-CVELitespeed Web Server 4.0.12 - Cross-Site Request Forgery (Add Admin) / Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109174. PoCs published by d1dn0t.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in LiteSpeed Web Server's admin interface, allowing an attacker to add an admin user via a crafted HTML form. The PoC includes a form that submits a POST request to create a new admin account with the username 'owned' and password 'password'.
Description
Litespeed Web Server 4.0.12 - Cross-Site Request Forgery (Add Admin) / Cross-Site Scripting
Exploits (1)
This exploit demonstrates a CSRF vulnerability in LiteSpeed Web Server's admin interface, allowing an attacker to add an admin user via a crafted HTML form. The PoC includes a form that submits a POST request to create a new admin account with the username 'owned' and password 'password'.