EIP-2026-100468
PRE-CVEOnline Work Order Suite Lite Edition - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100468. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates multiple reflected XSS vulnerabilities in Online Work Order Suite Lite Edition 3.10 by injecting arbitrary JavaScript via unsanitized input parameters in the URL.
Description
Online Work Order Suite Lite Edition - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Moudi · textwebappsasp
https://www.exploit-db.com/exploits/34492
This exploit demonstrates multiple reflected XSS vulnerabilities in Online Work Order Suite Lite Edition 3.10 by injecting arbitrary JavaScript via unsanitized input parameters in the URL.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Online Work Order Suite Lite Edition 3.10
No auth needed
Prerequisites:
Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026