
CVE-2025-52078 - Unauthenticated Arbitrary File Upload - Writebot SaaS React Template
This repository contains a proof-of-concept exploit for an Unauthenticated Arbitrary File Upload vulnerability found in the Writebot – AI Content Generator SaaS React Template.
🧠 Product Page:
ThemeForest – Writebot
The template exposes a file upload endpoint at:
POST /file-upload
Due to the lack of:
An attacker can upload a malicious PHP file disguised as an image, and execute arbitrary commands once it's written to a publicly accessible directory.
<meta name="csrf-token">bq.php shell disguised as image/jpegresult.txtrequestsbeautifulsoup4Install modules:
pip install requests beautifulsoup4
writebot.py # Main exploit script
list.txt # Domains
bq.php # Payload disguised as JPEG
result.txt # Shell URLs on success
Put target domains in list.txt:
test-web-dummy-site.ai
vulnerable.site
Ensure bq.php contains this format:
ÿØÿà
<?php
// Your code
?>
Run exploit:
python3 mass_uploader.py
Shell URLs saved to result.txt.
To mitigate:
This project is for educational and authorized testing purposes only.
Unauthorized use against websites you do not own or have permission to test is illegal and unethical.