EIP-2026-100559

PRE-CVE

SmarterMail 8.0 - Multiple Cross-Site Scripting Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100559. PoCs published by Hoyt LLC Research.

AI-analyzed exploit summary The document describes a stored XSS vulnerability in SmarterMail 8.0.4086.25048, where the `ctl00%24MPH%24wucContactInfo%24txtEmailAddress_SettingText` parameter is reflected unmodified in the response, allowing script injection. The analysis includes technical details such as the affected endpoint and payload behavior.

Description

SmarterMail 8.0 - Multiple Cross-Site Scripting Vulnerabilities

Exploits (1)

exploitdb WRITEUP
by Hoyt LLC Research · textwebappsasp
https://www.exploit-db.com/exploits/16975

The document describes a stored XSS vulnerability in SmarterMail 8.0.4086.25048, where the `ctl00%24MPH%24wucContactInfo%24txtEmailAddress_SettingText` parameter is reflected unmodified in the response, allowing script injection. The analysis includes technical details such as the affected endpoint and payload behavior.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: SmarterMail 8.0.4086.25048
Auth required
Prerequisites: Access to the vulnerable SmarterMail instance · Ability to submit crafted input to the affected parameter
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026