CVE-2016-10997
MEDIUMbeauty-premium 1.0.8 - Cross-Site Request Forgery with Arbitrary File Upload in sendmail.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-10997. PoCs published by Colette Chamberland.
AI-analyzed exploit summary This exploit demonstrates a file upload vulnerability in the WordPress Beauty Premium theme (v1.0.8) via a CSRF attack on the contact form. The PoC allows an attacker to upload arbitrary files to the WordPress upload directory without proper sanitization.
Description
The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.
Exploits (1)
This exploit demonstrates a file upload vulnerability in the WordPress Beauty Premium theme (v1.0.8) via a CSRF attack on the contact form. The PoC allows an attacker to upload arbitrary files to the WordPress upload directory without proper sanitization.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N