EIP-2026-109219

PRE-CVE

LoveCMS 1.6.2 - Cross-Site Request Forgery / Code Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109219. PoCs published by hiphop.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in LoveCMS 1.6.2 that allows arbitrary PHP code execution via the 'console.php' endpoint. The PoC crafts a malicious form submission that writes a PHP shell to the target system.

Description

LoveCMS 1.6.2 - Cross-Site Request Forgery / Code Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by hiphop · textwebappsphp
https://www.exploit-db.com/exploits/15849

This exploit demonstrates a CSRF vulnerability in LoveCMS 1.6.2 that allows arbitrary PHP code execution via the 'console.php' endpoint. The PoC crafts a malicious form submission that writes a PHP shell to the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: LoveCMS 1.6.2
No auth needed
Prerequisites: Target must be running LoveCMS 1.6.2 · Victim must visit the crafted HTML page
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026