EIP-2026-102487
PRE-CVEJForum 2.1.8 - 'bookmarks' Module Multiple HTML Injection Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102487. PoCs published by Adam Baldwin.
AI-analyzed exploit summary The code describes an HTML injection vulnerability in JForum 2.1.8, where user-supplied input is not properly sanitized, allowing attacker-supplied HTML and script code to execute in the context of the affected browser. The exploit involves crafting a malicious URL with XSS payloads in the 'description' and 'title' parameters.
Description
JForum 2.1.8 - 'bookmarks' Module Multiple HTML Injection Vulnerabilities
Exploits (1)
The code describes an HTML injection vulnerability in JForum 2.1.8, where user-supplied input is not properly sanitized, allowing attacker-supplied HTML and script code to execute in the context of the affected browser. The exploit involves crafting a malicious URL with XSS payloads in the 'description' and 'title' parameters.