EIP-2026-109237
PRE-CVEMadness Pro 1.14 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109237. PoCs published by bwall.
AI-analyzed exploit summary This Python script exploits an unauthenticated persistent XSS vulnerability in Madness Pro panel <= 1.14 by injecting a malicious script tag into the 'uid' parameter. The payload is URL-encoded and designed to execute arbitrary JavaScript, such as a BeEF hook, when rendered in the panel.
Description
Madness Pro 1.14 - Persistent Cross-Site Scripting
Exploits (1)
This Python script exploits an unauthenticated persistent XSS vulnerability in Madness Pro panel <= 1.14 by injecting a malicious script tag into the 'uid' parameter. The payload is URL-encoded and designed to execute arbitrary JavaScript, such as a BeEF hook, when rendered in the panel.