EIP-2026-106084
PRE-CVECommodityRentals Real Estate Script - 'txtsearch' HTML Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106084. PoCs published by Eyup CELIK.
AI-analyzed exploit summary The provided code demonstrates an HTML injection vulnerability in Real Estate Script, where user-supplied input is not properly sanitized. The payload includes a malicious `<img>` tag with an `onerror` event handler that triggers a JavaScript `alert(1)`, confirming the vulnerability.
Description
CommodityRentals Real Estate Script - 'txtsearch' HTML Injection
Exploits (1)
The provided code demonstrates an HTML injection vulnerability in Real Estate Script, where user-supplied input is not properly sanitized. The payload includes a malicious `<img>` tag with an `onerror` event handler that triggers a JavaScript `alert(1)`, confirming the vulnerability.