EIP-2026-104494
PRE-CVEWolters Kluwer TeamMate 3.1 - Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104494. PoCs published by Bhadresh Patel.
AI-analyzed exploit summary The provided code is a functional CSRF exploit for Wolters Kluwer TeamMate+ (CVE-2019-10253), demonstrating how an attacker can upload malicious files by enticing an authenticated user to visit a crafted HTML page. The exploit targets the 'DomainObjectDocumentUpload.ashx' endpoint, which lacks CSRF token validation.
Description
Wolters Kluwer TeamMate 3.1 - Cross-Site Request Forgery
Exploits (1)
The provided code is a functional CSRF exploit for Wolters Kluwer TeamMate+ (CVE-2019-10253), demonstrating how an attacker can upload malicious files by enticing an authenticated user to visit a crafted HTML page. The exploit targets the 'DomainObjectDocumentUpload.ashx' endpoint, which lacks CSRF token validation.