EIP-2026-109271
PRE-CVEMambo 4.6.5 - 'index.php' Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109271. PoCs published by Caddy-Dz.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Mambo CMS 4.6.5, allowing an attacker to trick an authenticated admin into submitting a malicious form that modifies user privileges. The PoC uses JavaScript to auto-submit a form that changes a user's group ID to an admin-level role.
Description
Mambo 4.6.5 - 'index.php' Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Mambo CMS 4.6.5, allowing an attacker to trick an authenticated admin into submitting a malicious form that modifies user privileges. The PoC uses JavaScript to auto-submit a form that changes a user's group ID to an admin-level role.