CVE-2026-1153

A vulnerability was detected in technical-laohu mpay up to 1.2.4. This affects an unknown function. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. The exploit is now public and may be used.
References
Link Resource
https://github.com/bdkuzma/vuln/issues/18 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.341746 Permissions Required VDB Entry
https://vuldb.com/?id.341746 Third Party Advisory VDB Entry
https://vuldb.com/?submit.735789 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:technical-laohu:mpay:*:*:*:*:*:*:*:*

History

06 Feb 2026, 19:51

Type Values Removed Values Added
References () https://github.com/bdkuzma/vuln/issues/18 - () https://github.com/bdkuzma/vuln/issues/18 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.341746 - () https://vuldb.com/?ctiid.341746 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.341746 - () https://vuldb.com/?id.341746 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.735789 - () https://vuldb.com/?submit.735789 - Third Party Advisory, VDB Entry
First Time Technical-laohu mpay
Technical-laohu
CPE cpe:2.3:a:technical-laohu:mpay:*:*:*:*:*:*:*:*

19 Jan 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-19 13:16

Updated : 2026-02-06 19:51


NVD link : CVE-2026-1153

Mitre link : CVE-2026-1153

CVE.ORG link : CVE-2026-1153


JSON object : View

Products Affected

technical-laohu

  • mpay
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization