Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators.
- http://chxsecurity.org/advisories/adv-2-mid.txt
- http://securityreason.com/securityalert/2896
No PoCs found on GitHub currently.