EIP-2026-100605

PRE-CVE

VisualSite CMS 1.3 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100605. PoCs published by Abysssec.

AI-analyzed exploit summary This advisory details two vulnerabilities in VisualSite CMS 1.3: a logical bug allowing admin login lockout via SQL injection and a persistent XSS in the admin section. The analysis includes vulnerable code snippets and exploitation steps.

Description

VisualSite CMS 1.3 - Multiple Vulnerabilities

Exploits (1)

exploitdb WRITEUP VERIFIED
by Abysssec · textwebappsasp
https://www.exploit-db.com/exploits/15106

This advisory details two vulnerabilities in VisualSite CMS 1.3: a logical bug allowing admin login lockout via SQL injection and a persistent XSS in the admin section. The analysis includes vulnerable code snippets and exploitation steps.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Reliable
Target: VisualSite CMS 1.3
No auth needed
Prerequisites: Access to the login page · Admin privileges for XSS exploitation
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026