EIP-2026-107751
PRE-CVEIcy Phoenix 1.3.0.53a - HTTP Referer Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107751. PoCs published by Saif El-Sherei.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Icy Phoenix 1.3.0.53a via the HTTP Referer header. The vulnerability allows an attacker to inject malicious JavaScript, which is then stored and executed when an admin views the 'HTTP referrers' section.
Description
Icy Phoenix 1.3.0.53a - HTTP Referer Persistent Cross-Site Scripting
Exploits (1)
exploitdb
WORKING POC
by Saif El-Sherei · textwebappsphp
https://www.exploit-db.com/exploits/16199
This exploit demonstrates a stored XSS vulnerability in Icy Phoenix 1.3.0.53a via the HTTP Referer header. The vulnerability allows an attacker to inject malicious JavaScript, which is then stored and executed when an admin views the 'HTTP referrers' section.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Icy Phoenix 1.3.0.53a
No auth needed
Prerequisites:
Ability to send crafted HTTP requests with a malicious Referer header
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026