EIP-2026-111764

PRE-CVE

REvolution 10.02 - Cross-Site Request Forgery

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111764. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in NPDS REvolution 10.02, allowing an attacker to inject PHP code into the 'footer_after' configuration file via a crafted HTTP request. The PoC uses an img tag to trigger the malicious request, potentially leading to remote code execution if the victim is an authenticated admin.

Description

REvolution 10.02 - Cross-Site Request Forgery

Exploits (1)

exploitdb WORKING POC
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/12726

This exploit demonstrates a CSRF vulnerability in NPDS REvolution 10.02, allowing an attacker to inject PHP code into the 'footer_after' configuration file via a crafted HTTP request. The PoC uses an img tag to trigger the malicious request, potentially leading to remote code execution if the victim is an authenticated admin.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: NPDS REvolution 10.02 and prior versions
Auth required
Prerequisites: Victim must be authenticated as an admin · Victim must visit a page containing the malicious img tag
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026