EIP-2026-109126
PRE-CVELifeType 1.2.10 - HTTP Referer Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109126. PoCs published by Saif El-Sherei.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Lifetype 1.2.10 due to improper sanitization of the HTTP Referer header. The PoC shows how an attacker can inject malicious JavaScript into the Referer header, which gets stored in the database and executed when viewed in blog statistics.
Description
LifeType 1.2.10 - HTTP Referer Persistent Cross-Site Scripting
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Lifetype 1.2.10 due to improper sanitization of the HTTP Referer header. The PoC shows how an attacker can inject malicious JavaScript into the Referer header, which gets stored in the database and executed when viewed in blog statistics.