EIP-2026-104169
PRE-CVEApplicure dotDefender 4.01-3 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104169. PoCs published by EnableSecurity.
AI-analyzed exploit summary This advisory details a cross-site scripting (XSS) vulnerability in Applicure dotDefender's log viewer, which fails to properly HTML-encode user-supplied input in HTTP headers. The vulnerability allows an attacker to inject malicious scripts that execute when viewed by an administrator.
Description
Applicure dotDefender 4.01-3 - Persistent Cross-Site Scripting
Exploits (1)
This advisory details a cross-site scripting (XSS) vulnerability in Applicure dotDefender's log viewer, which fails to properly HTML-encode user-supplied input in HTTP headers. The vulnerability allows an attacker to inject malicious scripts that execute when viewed by an administrator.