EIP-2026-107043
PRE-CVEFamily Connections CMS 2.3.2 - Persistent Cross-Site Scripting / XML Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107043. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Family Connections CMS 2.3.2 via the 'subject' POST parameter in messageboard.php and an XML injection vulnerability in /inc/getChat.php via the 'message' POST parameter. The PoC provides clickable links to trigger both vulnerabilities.
Description
Family Connections CMS 2.3.2 - Persistent Cross-Site Scripting / XML Injection
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Family Connections CMS 2.3.2 via the 'subject' POST parameter in messageboard.php and an XML injection vulnerability in /inc/getChat.php via the 'message' POST parameter. The PoC provides clickable links to trigger both vulnerabilities.