EIP-2026-106073

PRE-CVE

Cometchat - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106073. PoCs published by B127Y.

AI-analyzed exploit summary This exploit demonstrates two vulnerabilities in Cometchat: a code execution flaw via `call_user_func` in `chatrooms.php` and an XSS vulnerability in `handwrite/index.php`. Both are confirmed with live demo URLs.

Description

Cometchat - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by B127Y · textwebappsphp
https://www.exploit-db.com/exploits/24506

This exploit demonstrates two vulnerabilities in Cometchat: a code execution flaw via `call_user_func` in `chatrooms.php` and an XSS vulnerability in `handwrite/index.php`. Both are confirmed with live demo URLs.

Classification
Working Poc 90%
Attack Type
Rce | Xss
Complexity
Trivial
Reliability
Reliable
Target: Cometchat (all versions)
No auth needed
Prerequisites: Network access to the target Cometchat installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026