Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-28454. PoCs published by YSah44.
AI-analyzed exploit summary This repository contains a writeup describing a reflected XSS vulnerability in Limbas 4.3.36.1319. The vulnerability is triggered via the UPDATE/up_2_0.php page, allowing execution of arbitrary JavaScript code.
Description
Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).
Exploits (1)
nomisec
WRITEUP
1 stars
by YSah44 · poc
https://github.com/YSah44/Limbas-4.3.36.1319-is-vulnerable-to-Cross-Site-Scripting-XSS-
This repository contains a writeup describing a reflected XSS vulnerability in Limbas 4.3.36.1319. The vulnerability is triggered via the UPDATE/up_2_0.php page, allowing execution of arbitrary JavaScript code.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Limbas 4.3.36.1319
No auth needed
Prerequisites:
Access to the vulnerable Limbas instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
http://www.limbas.org/
Product, Third Party Advisory x_refsource_misc
https://sourceforge.net/projects/limbas/
Exploit, Third Party Advisory x_refsource_misc
https://github.com/YavuzSahbaz/Limbas-4.3.36.1319-is-vulnerable-to-Cross-Site-Scripting-XSS-
Scores
CVSS v3
6.1
EPSS
0.0111
EPSS Percentile
61.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
limbas/limbas
4.3.36.1319
Published
Apr 28, 2022
Tracked Since
Feb 18, 2026