EIP-2026-107380
PRE-CVEGenPortal - 'buscarCat.php' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107380. PoCs published by sl4xUz.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in GenPortal by injecting arbitrary script code via the 'palBuscar' parameter in the 'buscarCat.php' endpoint. The lack of input sanitization allows attackers to execute malicious scripts in the context of the affected site.
Description
GenPortal - 'buscarCat.php' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in GenPortal by injecting arbitrary script code via the 'palBuscar' parameter in the 'buscarCat.php' endpoint. The lack of input sanitization allows attackers to execute malicious scripts in the context of the affected site.