EIP-2026-110441

PRE-CVE

PacketFence Network Access Controller - Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110441. PoCs published by K053.

AI-analyzed exploit summary The exploit describes an input validation flaw in PacketFence's Login.php, specifically in the `check_input` and `check_sensitive_input` functions, which fail to properly sanitize user input, leading to XSS and HTML injection vulnerabilities. The PoC demonstrates how an attacker can inject malicious scripts via the username field.

Description

PacketFence Network Access Controller - Cross-Site Scripting

Exploits (1)

exploitdb WRITEUP VERIFIED
by K053 · textwebappsphp
https://www.exploit-db.com/exploits/10571

The exploit describes an input validation flaw in PacketFence's Login.php, specifically in the `check_input` and `check_sensitive_input` functions, which fail to properly sanitize user input, leading to XSS and HTML injection vulnerabilities. The PoC demonstrates how an attacker can inject malicious scripts via the username field.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PacketFence Network Access Controller
No auth needed
Prerequisites: Access to the login page of PacketFence
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026