EIP-2026-106015
PRE-CVECMSimple 3.3 - Cross-Site Scripting / Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106015. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates multiple XSS and CSRF vulnerabilities in CMSimple 3.3 by submitting crafted forms that inject malicious JavaScript into various fields, such as 'text', 'site_title', and 'template'. The PoC automatically submits these forms to trigger the vulnerabilities.
Description
CMSimple 3.3 - Cross-Site Scripting / Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates multiple XSS and CSRF vulnerabilities in CMSimple 3.3 by submitting crafted forms that inject malicious JavaScript into various fields, such as 'text', 'site_title', and 'template'. The PoC automatically submits these forms to trigger the vulnerabilities.