EIP-2026-107751

PRE-CVE

Icy Phoenix 1.3.0.53a - HTTP Referer Persistent Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107751. PoCs published by Saif El-Sherei.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Icy Phoenix 1.3.0.53a via the HTTP Referer header. The vulnerability allows an attacker to inject malicious JavaScript, which is then stored and executed when an admin views the 'HTTP referrers' section.

Description

Icy Phoenix 1.3.0.53a - HTTP Referer Persistent Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC
by Saif El-Sherei · textwebappsphp
https://www.exploit-db.com/exploits/16199

This exploit demonstrates a stored XSS vulnerability in Icy Phoenix 1.3.0.53a via the HTTP Referer header. The vulnerability allows an attacker to inject malicious JavaScript, which is then stored and executed when an admin views the 'HTTP referrers' section.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Icy Phoenix 1.3.0.53a
No auth needed
Prerequisites: Ability to send crafted HTTP requests with a malicious Referer header
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026