CVE-2024-46278

HIGH

Teedy 1.11 - Cross-Site Scripting via Management Console

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-46278. PoCs published by Ayato Shitomi @ Fore-Z co.ltd, ayato-shitomi.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Teedy 1.11, allowing an attacker to steal cookies and perform account takeover by tricking a victim into downloading a malicious HTML file. The PoC includes a script that sends a POST request to change the victim's password.

Description

Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

Exploits (2)

exploitdb WORKING POC
by Ayato Shitomi @ Fore-Z co.ltd · textwebappsmultiple
https://www.exploit-db.com/exploits/52228

This exploit demonstrates a stored XSS vulnerability in Teedy 1.11, allowing an attacker to steal cookies and perform account takeover by tricking a victim into downloading a malicious HTML file. The PoC includes a script that sends a POST request to change the victim's password.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Teedy 1.11
Auth required
Prerequisites: Attacker must have an account on the target Teedy instance · Victim must download and open the malicious HTML file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by ayato-shitomi · poc
https://github.com/ayato-shitomi/CVE-2024-46278-teedy_1.11_account-takeover

This repository contains a functional proof-of-concept for CVE-2024-46278, demonstrating an XSS vulnerability in Teedy 1.11 that allows account takeover via a crafted HTML file upload. The PoC includes JavaScript code that steals cookies and changes the victim's password upon file download.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Teedy 1.11
Auth required
Prerequisites: Attacker must have a valid account · Victim must download the malicious file
MITRE ATT&CK
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 8.4
EPSS 0.0090
EPSS Percentile 76.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
sismics/teedy 1.11
Published Oct 07, 2024
Tracked Since Feb 18, 2026