EIP-2026-103907
PRE-CVEGadu-Gadu Instant Messenger 6.0 - File Transfer Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103907. PoCs published by Kacper Szczesniak.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Gadu-Gadu Instant Messenger by injecting malicious JavaScript via an input field. The payload loads an external script (x.js) that manipulates the DOM to hide elements and automatically trigger file open requests.
Description
Gadu-Gadu Instant Messenger 6.0 - File Transfer Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Gadu-Gadu Instant Messenger by injecting malicious JavaScript via an input field. The payload loads an external script (x.js) that manipulates the DOM to hide elements and automatically trigger file open requests.