EIP-2026-108261
PRE-CVEJoomla! Component com_alfcontact 1.9.3 - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108261. PoCs published by Jose Carlos de Arriba.
AI-analyzed exploit summary The provided code demonstrates a cross-site scripting (XSS) vulnerability in the Joomla! 'com_alfcontact' extension by injecting malicious JavaScript into multiple input parameters. The payload triggers a prompt displaying the user's cookies when the mouse hovers over the affected fields.
Description
Joomla! Component com_alfcontact 1.9.3 - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The provided code demonstrates a cross-site scripting (XSS) vulnerability in the Joomla! 'com_alfcontact' extension by injecting malicious JavaScript into multiple input parameters. The payload triggers a prompt displaying the user's cookies when the mouse hovers over the affected fields.