Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-108039. PoCs published by Metropolis.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Jaow CMS 2.4.8, where an attacker can inject arbitrary script code via the 'add_ons' parameter in the 'add_ons.php' file. The vulnerability allows for the execution of malicious scripts in the context of the affected site, potentially leading to credential theft or other attacks.
Description
Jaow CMS - 'add_ons' Cross-Site Scripting
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Jaow CMS 2.4.8, where an attacker can inject arbitrary script code via the 'add_ons' parameter in the 'add_ons.php' file. The vulnerability allows for the execution of malicious scripts in the context of the affected site, potentially leading to credential theft or other attacks.