PT-2026-40618 · Easy2Pilot V7 · Easy2Pilot

·

CVE-2020-37217

·

Published

2026-05-13

·

Updated

2026-05-13

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the admin.php?action=add user endpoint with POST requests containing username and password parameters to create new administrative accounts without explicit user consent.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-37217

Affected Products

Easy2Pilot