EIP-2026-101316
PRE-CVEICT Protege GX/WX 2.08 - Stored Cross-Site Scripting (XSS)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101316. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authenticated stored XSS vulnerability in ICT Protege GX/WX 2.08, where the 'Name' parameter in the Daylight Savings scheduling feature fails to sanitize input, allowing arbitrary script execution. The PoC includes decrypted and encrypted request examples, along with encryption/decryption functions used by the application.
Description
ICT Protege GX/WX 2.08 - Stored Cross-Site Scripting (XSS)
Exploits (1)
This exploit demonstrates an authenticated stored XSS vulnerability in ICT Protege GX/WX 2.08, where the 'Name' parameter in the Daylight Savings scheduling feature fails to sanitize input, allowing arbitrary script execution. The PoC includes decrypted and encrypted request examples, along with encryption/decryption functions used by the application.