EIP-2026-102517

PRE-CVE

OpenEMM-2013 8.10.380.hf13.0.066 - SOAP SQL Injection / Persistent Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102517. PoCs published by drone.

AI-analyzed exploit summary This exploit targets OpenEMM 2013 (8.10.380.hf13.0.066) via SOAP-based SQL injection and stored XSS. It leverages a WSDL proxy to interact with the vulnerable SOAP endpoint, allowing unauthorized data extraction, manipulation, and deletion of subscribers/mailing lists.

Description

OpenEMM-2013 8.10.380.hf13.0.066 - SOAP SQL Injection / Persistent Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC
by drone · pythonwebappsjsp
https://www.exploit-db.com/exploits/27187

This exploit targets OpenEMM 2013 (8.10.380.hf13.0.066) via SOAP-based SQL injection and stored XSS. It leverages a WSDL proxy to interact with the vulnerable SOAP endpoint, allowing unauthorized data extraction, manipulation, and deletion of subscribers/mailing lists.

Classification
Working Poc 95%
Attack Type
Sqli | Xss
Complexity
Moderate
Reliability
Reliable
Target: OpenEMM 2013 (8.10.380.hf13.0.066)
No auth needed
Prerequisites: Network access to the OpenEMM SOAP endpoint (port 8080) · Presence of the 'ws.wsdl' file in the local directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026