Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative accounts by submitting forged POST requests. Attackers can craft malicious web pages that submit POST requests to createuser.php with parameters including username, password, name, surname, and privileges set to 1 for administrator access.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/45815 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/easyndexer-cross-site-request-forgery-via-createuserphp | Broken Link |
Configurations
History
16 Mar 2026, 19:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/45815 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/easyndexer-cross-site-request-forgery-via-createuserphp - Broken Link | |
| CPE | cpe:2.3:a:rul10:easyndexer:1.0:*:*:*:*:*:*:* | |
| First Time |
Rul10 easyndexer
Rul10 |
|
| Summary |
|
06 Mar 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-06 13:16
Updated : 2026-03-16 19:06
NVD link : CVE-2018-25190
Mitre link : CVE-2018-25190
CVE.ORG link : CVE-2018-25190
JSON object : View
Products Affected
rul10
- easyndexer
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
