EasyImages Cross-Site Request Forgery Vulnerability Allowing Privilege Escalation to Administrator

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the EasyImages application, specifically in version 2.0 through 2.8.6, within the admin/admin.inc.php component. This vulnerability allows attackers to escalate privileges to Administrator by manipulating users into interacting with a malicious web page.

Impact

Exploitation of this vulnerability allows for unauthorized password changes of administrators, followed by remote code execution on the server.

Reproduction

To reproduce this vulnerability, an attacker must create a malicious HTML page that includes a CSRF payload. This page should be designed to automatically submit a POST request to the vulnerable admin endpoint, changing the password of an administrator to a value controlled by the attacker. Once the password is changed, the attacker can log into the admin panel, upload a web shell, and execute it to gain remote code execution on the server.

Added: Dec 11, 2025, 5:22 PM
Updated: Dec 11, 2025, 5:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.8
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.