EIP-2026-110759

PRE-CVE

PHP Server Monitor 3.1.1 - Cross-Site Request Forgery / Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110759. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in PHP Server Monitor 3.1.1, allowing a basic user to escalate privileges to admin by tricking an admin into submitting a crafted form. The attack leverages the absence of CSRF protection to modify the user's privilege level in the database.

Description

PHP Server Monitor 3.1.1 - Cross-Site Request Forgery / Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · htmlwebappsphp
https://www.exploit-db.com/exploits/38574

This exploit demonstrates a CSRF vulnerability in PHP Server Monitor 3.1.1, allowing a basic user to escalate privileges to admin by tricking an admin into submitting a crafted form. The attack leverages the absence of CSRF protection to modify the user's privilege level in the database.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: PHP Server Monitor 3.1.1
Auth required
Prerequisites: Victim must be authenticated as an admin · Attacker must have a valid user account · Victim must visit a malicious link or page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026