EIP-2026-103306
PRE-CVEOracle Siebel CRM 19.0 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103306. PoCs published by Sarath Nair.
AI-analyzed exploit summary This is a technical writeup detailing a persistent XSS vulnerability in Oracle Siebel CRM 19.0 and prior versions, caused by insecure file upload functionality allowing HTML files with JavaScript payloads. The exploit requires authentication and involves uploading a malicious HTML file via the 'Activity Attachment View' feature.
Description
Oracle Siebel CRM 19.0 - Persistent Cross-Site Scripting
Exploits (1)
This is a technical writeup detailing a persistent XSS vulnerability in Oracle Siebel CRM 19.0 and prior versions, caused by insecure file upload functionality allowing HTML files with JavaScript payloads. The exploit requires authentication and involves uploading a malicious HTML file via the 'Activity Attachment View' feature.