EIP-2026-105807
PRE-CVEChamilo LMS 1.11.8 - 'firstname' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105807. PoCs published by cakes.
AI-analyzed exploit summary The exploit demonstrates a persistent XSS vulnerability in Chamilo LMS 1.11.8 by injecting malicious JavaScript into the 'firstname' and 'lastname' fields during user registration. The PoC includes a crafted HTTP POST request that triggers the XSS payload when processed by the application.
Description
Chamilo LMS 1.11.8 - 'firstname' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a persistent XSS vulnerability in Chamilo LMS 1.11.8 by injecting malicious JavaScript into the 'firstname' and 'lastname' fields during user registration. The PoC includes a crafted HTTP POST request that triggers the XSS payload when processed by the application.