EIP-2026-113247

PRE-CVE

Webbler CMS 3.1.3 - Mail A Friend Open Email Relay

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113247. PoCs published by Adrian Pastor.

AI-analyzed exploit summary This exploit demonstrates an open-email-relay vulnerability in webbler 3.1.3, allowing attackers to send arbitrary unsolicited bulk email or forge messages from trusted mail servers via a crafted HTML form.

Description

Webbler CMS 3.1.3 - Mail A Friend Open Email Relay

Exploits (1)

exploitdb WORKING POC VERIFIED
by Adrian Pastor · htmlwebappsphp
https://www.exploit-db.com/exploits/30379

This exploit demonstrates an open-email-relay vulnerability in webbler 3.1.3, allowing attackers to send arbitrary unsolicited bulk email or forge messages from trusted mail servers via a crafted HTML form.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: webbler 3.1.3
No auth needed
Prerequisites: Access to the vulnerable webbler instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026