EIP-2026-110606
PRE-CVEPhorum 5.2 - '/admin/users.php' Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110606. PoCs published by voodoo-labs.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Phorum by injecting malicious JavaScript via the email parameter in an admin user creation request. The payload triggers an alert dialog, proving arbitrary script execution in the context of an admin session.
Description
Phorum 5.2 - '/admin/users.php' Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Phorum by injecting malicious JavaScript via the email parameter in an admin user creation request. The payload triggers an alert dialog, proving arbitrary script execution in the context of an admin session.