EIP-2026-102503
PRE-CVEManageEngine Support Center Plus 7908 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102503. PoCs published by xistence.
AI-analyzed exploit summary The exploit demonstrates an arbitrary file upload vulnerability (bypassing extension checks) and XSS (reflected and stored) in ManageEngine Support Center Plus <=7908. The file upload allows unauthenticated attackers to upload malicious files, while XSS enables script execution in user contexts.
Description
ManageEngine Support Center Plus 7908 - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates an arbitrary file upload vulnerability (bypassing extension checks) and XSS (reflected and stored) in ManageEngine Support Center Plus <=7908. The file upload allows unauthenticated attackers to upload malicious files, while XSS enables script execution in user contexts.