MegaBIP Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in MegaBIP versions prior to 5.15. The issue arises because the form located at '/edytor/index.php?id=7,7,0' lacks proper protection against CSRF attacks. This vulnerability could be exploited by tricking a user into visiting a malicious website that sends a POST request to the vulnerable endpoint. If the user is a logged-in administrator, this could result in the unauthorized creation of new accounts with administrative privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized account creation with administrative rights on the affected MegaBIP website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.