EIP-2026-100559
PRE-CVESmarterMail 8.0 - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100559. PoCs published by Hoyt LLC Research.
AI-analyzed exploit summary The document describes a stored XSS vulnerability in SmarterMail 8.0.4086.25048, where the `ctl00%24MPH%24wucContactInfo%24txtEmailAddress_SettingText` parameter is reflected unmodified in the response, allowing script injection. The analysis includes technical details such as the affected endpoint and payload behavior.
Description
SmarterMail 8.0 - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The document describes a stored XSS vulnerability in SmarterMail 8.0.4086.25048, where the `ctl00%24MPH%24wucContactInfo%24txtEmailAddress_SettingText` parameter is reflected unmodified in the response, allowing script injection. The analysis includes technical details such as the affected endpoint and payload behavior.