EIP-2026-105902

PRE-CVE

Clever Copy 2.0/3.0 - Multiple HTML Injection Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105902. PoCs published by Aliaksandr Hartsuyeu.

AI-analyzed exploit summary The provided text describes an HTML injection vulnerability in Clever Copy, where user-supplied input is not properly sanitized, allowing execution of arbitrary HTML and script code. The example demonstrates how an attacker could inject malicious content via HTTP headers like Referer and X-Forwarded-For.

Description

Clever Copy 2.0/3.0 - Multiple HTML Injection Vulnerabilities

Exploits (1)

exploitdb WRITEUP VERIFIED
by Aliaksandr Hartsuyeu · textwebappsphp
https://www.exploit-db.com/exploits/27207

The provided text describes an HTML injection vulnerability in Clever Copy, where user-supplied input is not properly sanitized, allowing execution of arbitrary HTML and script code. The example demonstrates how an attacker could inject malicious content via HTTP headers like Referer and X-Forwarded-For.

Classification
Writeup 80%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: Clever Copy (version unspecified)
No auth needed
Prerequisites: Access to the target application · Ability to send crafted HTTP requests
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026