EIP-2026-100096
PRE-CVEActivedition - '/activedition/aelogin.asp' Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100096. PoCs published by Richard Brain.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in Activedition 4.0 by injecting malicious scripts into the 'workflow' and 'pageid' parameters of the 'aelogin.asp' endpoint. The payloads include alert-based cookie theft and iframe injection, confirming the lack of input sanitization.
Description
Activedition - '/activedition/aelogin.asp' Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in Activedition 4.0 by injecting malicious scripts into the 'workflow' and 'pageid' parameters of the 'aelogin.asp' endpoint. The payloads include alert-based cookie theft and iframe injection, confirming the lack of input sanitization.