EIP-2026-105209
PRE-CVEappRain Quick Start Edition Core Edition Multiple 0.1.4-Alpha - Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105209. PoCs published by SecPod Research.
AI-analyzed exploit summary This is a detailed technical writeup describing multiple persistent XSS vulnerabilities in appRain Quick Start and Core Editions. It includes proof-of-concept HTTP requests demonstrating how malicious scripts can be injected via unsanitized parameters.
Description
appRain Quick Start Edition Core Edition Multiple 0.1.4-Alpha - Cross-Site Scripting
Exploits (1)
exploitdb
WRITEUP
by SecPod Research · textwebappsphp
https://www.exploit-db.com/exploits/17508
This is a detailed technical writeup describing multiple persistent XSS vulnerabilities in appRain Quick Start and Core Editions. It includes proof-of-concept HTTP requests demonstrating how malicious scripts can be injected via unsanitized parameters.
Classification
Writeup 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
appRain 0.1.4-Alpha (Quick Start Edition), appRain-d-0.1.3 (Core Edition) and prior versions
Auth required
Prerequisites:
Access to vulnerable appRain instance · For POC 2: Valid authentication credentials
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026