vendor:
Diary/Notebook Site5 Wordpress Theme
by:
@bwallHatesTwits
7,5
CVSS
HIGH
Email Spoofing
20
CWE
Product Name: Diary/Notebook Site5 Wordpress Theme
Affected Version From: Not Documented
Affected Version To: Not Documented
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 3.2
2012
Diary/Notebook Site5 WordPress Theme – Email Spoofing
A vulnerability exists in the Diary/Notebook Site5 Wordpress Theme which allows an attacker to send spoofed emails. This vulnerability is due to the lack of proper validation of the sender's email address in the sendmail.php script. An attacker can exploit this vulnerability by sending a crafted POST request to the sendmail.php script with a spoofed email address as the sender. This can be used to send malicious emails to unsuspecting users.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of the Diary/Notebook Site5 Wordpress Theme.