Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-110285. PoCs published by Curesec Research Team.
AI-analyzed exploit summary This is a functional CSRF exploit for Opendocman 1.3.4, demonstrating how an attacker can add a new admin user by tricking an authenticated admin into submitting a crafted form. The PoC includes a complete HTML form with hidden fields to exploit the lack of CSRF protection.
Description
OpenDocMan 1.3.4 - Cross-Site Request Forgery
Exploits (1)
This is a functional CSRF exploit for Opendocman 1.3.4, demonstrating how an attacker can add a new admin user by tricking an authenticated admin into submitting a crafted form. The PoC includes a complete HTML form with hidden fields to exploit the lack of CSRF protection.