EIP-2026-108449
PRE-CVEJoomla! Component com_mtree 2.1.6 - Overwrite Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108449. PoCs published by jdc.
AI-analyzed exploit summary This PHP script demonstrates a CSRF vulnerability in Mosets Tree 2.1.6 for Joomla, allowing an attacker to overwrite template files by tricking an admin into visiting a malicious page. The exploit submits a crafted POST request to save arbitrary PHP code into a template file.
Description
Joomla! Component com_mtree 2.1.6 - Overwrite Cross-Site Request Forgery
Exploits (1)
This PHP script demonstrates a CSRF vulnerability in Mosets Tree 2.1.6 for Joomla, allowing an attacker to overwrite template files by tricking an admin into visiting a malicious page. The exploit submits a crafted POST request to save arbitrary PHP code into a template file.