EIP-2026-111428
PRE-CVEPostNuke 0.723 - 'user.php' UNAME Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111428. PoCs published by David F. Madrid.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in PostNuke's 'user.php' script due to insufficient sanitization of URI parameters. The provided URL injects malicious JavaScript code via the 'uname' parameter, which executes in the context of the victim's browser.
Description
PostNuke 0.723 - 'user.php' UNAME Cross-Site Scripting
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in PostNuke's 'user.php' script due to insufficient sanitization of URI parameters. The provided URL injects malicious JavaScript code via the 'uname' parameter, which executes in the context of the victim's browser.