EIP-2026-107651
PRE-CVEHotel Management System 1.0 - Cross-Site Scripting (XSS) Arbitrary File Upload Remote Code Execution (RCE)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107651. PoCs published by Merbin Russel.
AI-analyzed exploit summary This exploit leverages a Blind Cross-Site Scripting (BXSS) vulnerability to steal an admin's session cookie, then uses that session to upload a PHP reverse shell for Remote Code Execution (RCE). It requires admin interaction to trigger the BXSS payload.
Description
Hotel Management System 1.0 - Cross-Site Scripting (XSS) Arbitrary File Upload Remote Code Execution (RCE)
Exploits (1)
This exploit leverages a Blind Cross-Site Scripting (BXSS) vulnerability to steal an admin's session cookie, then uses that session to upload a PHP reverse shell for Remote Code Execution (RCE). It requires admin interaction to trigger the BXSS payload.