EIP-2026-113408
PRE-CVEWHMCompleteSolution (WHMCS) 3.x < 4.0.x - 'cart.php' Local File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113408. PoCs published by Lagripe-Dz & Mca-Crb.
AI-analyzed exploit summary The exploit demonstrates a local file disclosure vulnerability in WHMCS (WHMCompleteSolution) versions 3.x.x and 4.0.x. By manipulating the 'templatefile' parameter in cart.php, an attacker can read arbitrary files on the server due to insufficient input validation.
Description
WHMCompleteSolution (WHMCS) 3.x < 4.0.x - 'cart.php' Local File Disclosure
Exploits (1)
The exploit demonstrates a local file disclosure vulnerability in WHMCS (WHMCompleteSolution) versions 3.x.x and 4.0.x. By manipulating the 'templatefile' parameter in cart.php, an attacker can read arbitrary files on the server due to insufficient input validation.