EIP-2026-104627
PRE-CVECroogo CMS 1.3.4 - Multiple HTML Injection Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104627. PoCs published by Chokri Ben Achor.
AI-analyzed exploit summary This exploit demonstrates HTML injection vulnerabilities in Croogo CMS 1.3.4, allowing attacker-supplied HTML and script code to execute in the context of the affected browser. The PoC includes payloads for XSS via iframe injection in admin user and role management pages.
Description
Croogo CMS 1.3.4 - Multiple HTML Injection Vulnerabilities
Exploits (1)
This exploit demonstrates HTML injection vulnerabilities in Croogo CMS 1.3.4, allowing attacker-supplied HTML and script code to execute in the context of the affected browser. The PoC includes payloads for XSS via iframe injection in admin user and role management pages.