CVE-2016-7980
HIGHSPIP < 3.1.2 - Cross-Site Request Forgery via XML Validator
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-7980. PoCs published by Sysdream.
AI-analyzed exploit summary This is a writeup describing a CSRF vulnerability in SPIP 3.1.2 that allows an attacker to execute arbitrary code by tricking an administrator into visiting a malicious link. The vulnerability is related to CVE-2016-7998 and affects versions <= 3.1.2.
Description
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.
Exploits (1)
This is a writeup describing a CSRF vulnerability in SPIP 3.1.2 that allows an attacker to execute arbitrary code by tricking an administrator into visiting a malicious link. The vulnerability is related to CVE-2016-7998 and affects versions <= 3.1.2.
References (8)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H