EIP-2026-107874

PRE-CVE

Insurance Management System PHP and MySQL 1.0 - Multiple Stored XSS

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107874. PoCs published by Hakkı TOKLU.

AI-analyzed exploit summary This exploit demonstrates multiple stored XSS vulnerabilities in Insurance Management System PHP and MySQL 1.0. It provides specific payloads and HTTP request examples for injecting malicious scripts into user input fields, which are later executed when an admin views the affected pages.

Description

Insurance Management System PHP and MySQL 1.0 - Multiple Stored XSS

Exploits (1)

exploitdb WORKING POC
by Hakkı TOKLU · textwebappsphp
https://www.exploit-db.com/exploits/51920

This exploit demonstrates multiple stored XSS vulnerabilities in Insurance Management System PHP and MySQL 1.0. It provides specific payloads and HTTP request examples for injecting malicious scripts into user input fields, which are later executed when an admin views the affected pages.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Insurance Management System PHP and MySQL 1.0
Auth required
Prerequisites: Access to the application · Valid session cookies for authenticated actions
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026