EIP-2026-111903

PRE-CVE

Saurus CMS Admin Panel - Multiple Cross-Site Request Forgery Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111903. PoCs published by Fady Mohammed Osman.

AI-analyzed exploit summary The exploit demonstrates a CSRF vulnerability in Saurus CMS 4.7.0, allowing an attacker to change site information and user passwords via crafted HTTP requests. The PoC uses simple HTML with img tags to trigger the vulnerable endpoints without user interaction.

Description

Saurus CMS Admin Panel - Multiple Cross-Site Request Forgery Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by Fady Mohammed Osman · htmlwebappsphp
https://www.exploit-db.com/exploits/14644

The exploit demonstrates a CSRF vulnerability in Saurus CMS 4.7.0, allowing an attacker to change site information and user passwords via crafted HTTP requests. The PoC uses simple HTML with img tags to trigger the vulnerable endpoints without user interaction.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Saurus CMS 4.7.0
No auth needed
Prerequisites: Victim must be authenticated in the admin session · Attacker must lure victim to a malicious page
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026