EIP-2026-113316
PRE-CVEWebiness Inventory 2.3 - Arbitrary File Upload / Cross-Site Request Forgery (Add Admin)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113316. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Webiness Inventory 2.3, allowing an attacker to upload a malicious PHP file via a POST request to `WsSaveToModel.php` and execute it. It also includes a CSRF-based admin addition technique by manipulating user data.
Description
Webiness Inventory 2.3 - Arbitrary File Upload / Cross-Site Request Forgery (Add Admin)
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in Webiness Inventory 2.3, allowing an attacker to upload a malicious PHP file via a POST request to `WsSaveToModel.php` and execute it. It also includes a CSRF-based admin addition technique by manipulating user data.