CVE-2024-22855

MEDIUM

ITSS iMLog < 1.308 - Stored Cross-Site Scripting via User Maintenance Last Name Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-22855. PoCs published by Gabriel Felipe.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in iMLog < 1.307 via the 'User Management' feature. An attacker can inject malicious JavaScript into the 'Last Name' field, which executes when an admin views the 'User Maintenance' page.

Description

A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.

Exploits (1)

exploitdb WORKING POC
by Gabriel Felipe · textwebappsphp
https://www.exploit-db.com/exploits/52025

This exploit demonstrates a persistent XSS vulnerability in iMLog < 1.307 via the 'User Management' feature. An attacker can inject malicious JavaScript into the 'Last Name' field, which executes when an admin views the 'User Maintenance' page.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: iMLog < 1.307
Auth required
Prerequisites: Valid user account credentials · Access to the 'User Maintenance' feature
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry
https://www.exploit-db.com/exploits/52025

Scores

CVSS v3 5.4
EPSS 0.0017
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
itssglobal/imlog < 1.308
Published Jun 12, 2024
Tracked Since Feb 18, 2026