CVE-2024-32830
HIGHBuddyForms <= 2.8.8 - Path Traversal and Server-Side Request Forgery
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-32830. PoCs published by ptrstr.
AI-analyzed exploit summary This repository contains a functional PoC for CVE-2024-32830, exploiting a bypass in PHP's `getimagesize` function via crafted `image/vnd.wap.wbmp` headers and PHP filter chains to leak arbitrary files. The PoC demonstrates file exfiltration by encoding and wrapping the target file in a valid WBMP structure.
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.
Exploits (1)
This repository contains a functional PoC for CVE-2024-32830, exploiting a bypass in PHP's `getimagesize` function via crafted `image/vnd.wap.wbmp` headers and PHP filter chains to leak arbitrary files. The PoC demonstrates file exfiltration by encoding and wrapping the target file in a valid WBMP structure.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N