Exagate SYSGuard 6001 Cross-Site Request Forgery Vulnerability Allowing Unauthorized Admin Account Creation

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Exagate SYSGuard version 6001. This vulnerability allows attackers to create unauthorized admin accounts by tricking users into submitting a malicious HTML form. The crafted form is sent to 'kulyon.php', where it adds a new user with administrative privileges without the victim's consent.

Impact

Exploitation of this vulnerability allows for the creation of unauthorized admin accounts, potentially leading to unauthorized access and privileges within the application.

Reproduction

To reproduce this vulnerability, a CSRF attack can be executed by sending a crafted HTML form to the target application. The form should be set to submit to 'kulyon.php' via POST method, including hidden fields for 'username', 'password', 'privilege', and a submit button. When the victim unknowingly submits this form, an admin account is created with the specified credentials.

Added: Feb 5, 2026, 7:41 PM
Updated: Feb 5, 2026, 9:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.1
remediation
0.0
relevance
2.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.