A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Administrator via user interaction with a malicious web page.
https://gist.github.com/CongSec/a6c8b15878f19647dbd26c22b47bac65