EIP-2026-109201
PRE-CVElog1 CMS 2.0 - Session Handling Remote Security Bypass / Remote File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109201. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in log1 CMS 2.0 by injecting malicious JavaScript into the 'content' parameter, which is then submitted via a hidden form. The vulnerability allows arbitrary script execution in the context of the webserver process.
Description
log1 CMS 2.0 - Session Handling Remote Security Bypass / Remote File Inclusion
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in log1 CMS 2.0 by injecting malicious JavaScript into the 'content' parameter, which is then submitted via a hidden form. The vulnerability allows arbitrary script execution in the context of the webserver process.