EIP-2026-104292
PRE-CVEJForum 2.1.8 BookMarks - Cross-Site Request Forgery / Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104292. PoCs published by Adam Baldwin.
AI-analyzed exploit summary This advisory describes a CSRF and XSS vulnerability in JForum 2.1.8's bookmarks feature. The exploit involves tricking an authenticated user into visiting a crafted URL, which inserts a malicious bookmark with an XSS payload that executes when the user views their bookmarks.
Description
JForum 2.1.8 BookMarks - Cross-Site Request Forgery / Cross-Site Scripting
Exploits (1)
This advisory describes a CSRF and XSS vulnerability in JForum 2.1.8's bookmarks feature. The exploit involves tricking an authenticated user into visiting a crafted URL, which inserts a malicious bookmark with an XSS payload that executes when the user views their bookmarks.