Description
Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the admin.php?action=add_user endpoint with POST requests containing username and password parameters to create new administrative accounts without explicit user consent.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
indoushka
References
www.exploit-db.com/exploits/48099 (ExploitDB-48099)
easy2pilot-v7.com/ (Official Product Homepage)
www.vulncheck.com/...ross-site-request-forgery-via-admin-php (VulnCheck Advisory: Easy2Pilot 7 Cross-Site Request Forgery via admin.php)