EIP-2026-105277

PRE-CVE

Atmail Webmail 7.2 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105277. PoCs published by smash.

AI-analyzed exploit summary The exploit demonstrates multiple XSS (Cross-Site Scripting) and FPD (Full Path Disclosure) vulnerabilities in Atmail Webmail versions >=7.2. It includes detailed request examples and injection points for both reflected and persistent XSS attacks, as well as a path disclosure technique.

Description

Atmail Webmail 7.2 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by smash · textwebappsphp
https://www.exploit-db.com/exploits/34585

The exploit demonstrates multiple XSS (Cross-Site Scripting) and FPD (Full Path Disclosure) vulnerabilities in Atmail Webmail versions >=7.2. It includes detailed request examples and injection points for both reflected and persistent XSS attacks, as well as a path disclosure technique.

Classification
Working Poc 95%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Atmail Webmail >=7.2
No auth needed
Prerequisites: Access to the target webmail interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026