EIP-2026-106252

PRE-CVE

CS-Cart 4.3.10 - XML External Entity Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106252. PoCs published by 0x4148.

AI-analyzed exploit summary The exploit demonstrates two XXE (XML External Entity) vulnerabilities in CS-Cart <= 4.3.10, affecting the Twigmo addon and Amazon payment module. It includes functional PoC code that triggers outbound HTTP requests to an attacker-controlled server via crafted XML payloads.

Description

CS-Cart 4.3.10 - XML External Entity Injection

Exploits (1)

exploitdb WORKING POC
by 0x4148 · textwebappsphp
https://www.exploit-db.com/exploits/40770

The exploit demonstrates two XXE (XML External Entity) vulnerabilities in CS-Cart <= 4.3.10, affecting the Twigmo addon and Amazon payment module. It includes functional PoC code that triggers outbound HTTP requests to an attacker-controlled server via crafted XML payloads.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: CS-Cart <= 4.3.10
No auth needed
Prerequisites: Twigmo addon activated for XXE I · Amazon payment method activated for XXE II
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026