EIP-2026-102373
PRE-CVEH-Sphere 2.x - HTML Template Inclusion Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102373. PoCs published by Lorenzo Hernandez Garcia-Hierro.
AI-analyzed exploit summary This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in H-Sphere's Hosting Control Panel. The vulnerabilities arise from improper filtering of HTML and script code in template-related parameters, allowing arbitrary script execution in the context of a logged-in user's session.
Description
H-Sphere 2.x - HTML Template Inclusion Cross-Site Scripting
Exploits (1)
This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in H-Sphere's Hosting Control Panel. The vulnerabilities arise from improper filtering of HTML and script code in template-related parameters, allowing arbitrary script execution in the context of a logged-in user's session.