CVE-2025-26159
MEDIUMlaravel-starter < 11.11.0 - Stored Cross-Site Scripting in Tags Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-26159. PoCs published by godBADTRY.
AI-analyzed exploit summary This PoC demonstrates an XSS vulnerability in Laravel Starter by extracting session cookies via a malicious script injected into the tag name field. The server component listens for and decodes stolen cookies sent via a fetch request.
Description
Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.
Exploits (1)
This PoC demonstrates an XSS vulnerability in Laravel Starter by extracting session cookies via a malicious script injected into the tag name field. The server component listens for and decodes stolen cookies sent via a fetch request.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N