EIP-2026-107153
PRE-CVEFlippy DamnFacts - Viral Fun Facts Sharing Script 1.1.0 - Cross-Site Scripting / Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107153. PoCs published by L0RD.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in the 'Birthday' field of the user profile and a CSRF vulnerability in the profile update functionality of Flippy DamnFacts 1.1.0. The XSS payload triggers an alert box with the user's cookies, while the CSRF PoC automatically submits a form to update the user's profile without their consent.
Description
Flippy DamnFacts - Viral Fun Facts Sharing Script 1.1.0 - Cross-Site Scripting / Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in the 'Birthday' field of the user profile and a CSRF vulnerability in the profile update functionality of Flippy DamnFacts 1.1.0. The XSS payload triggers an alert box with the user's cookies, while the CSRF PoC automatically submits a form to update the user's profile without their consent.