EIP-2026-112122
PRE-CVESimple Online Hotel Reservation System - Cross-Site Request Forgery (Add Admin)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112122. PoCs published by Mr Winst0n.
AI-analyzed exploit summary This is a functional CSRF PoC for the Simple Online Hotel Reservation System, allowing an attacker to trick an authenticated admin into submitting a form that adds a new admin account. The exploit leverages a lack of CSRF tokens in the admin account creation endpoint.
Description
Simple Online Hotel Reservation System - Cross-Site Request Forgery (Add Admin)
Exploits (1)
This is a functional CSRF PoC for the Simple Online Hotel Reservation System, allowing an attacker to trick an authenticated admin into submitting a form that adds a new admin account. The exploit leverages a lack of CSRF tokens in the admin account creation endpoint.