EIP-2026-111048
PRE-CVEPHPfileNavigator 2.3.3 - Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111048. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This is a functional CSRF exploit for PHPfileNavigator v2.3.3 that adds arbitrary admin accounts by submitting a crafted POST request without requiring a valid CSRF token. The exploit leverages the absence of session validation to create a new user with administrative privileges.
Description
PHPfileNavigator 2.3.3 - Cross-Site Request Forgery
Exploits (1)
This is a functional CSRF exploit for PHPfileNavigator v2.3.3 that adds arbitrary admin accounts by submitting a crafted POST request without requiring a valid CSRF token. The exploit leverages the absence of session validation to create a new user with administrative privileges.