EIP-2026-111772

PRE-CVE

Ricoh Web Image Monitor 2.03 - Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111772. PoCs published by thelightcosine.

AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in Ricoh Web Image Monitor by injecting a malicious script via a crafted GET request. The payload closes an existing script tag and injects an alert, confirming arbitrary JavaScript execution in the context of the affected site.

Description

Ricoh Web Image Monitor 2.03 - Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by thelightcosine · textwebappsphp
https://www.exploit-db.com/exploits/34990

The exploit demonstrates a reflected XSS vulnerability in Ricoh Web Image Monitor by injecting a malicious script via a crafted GET request. The payload closes an existing script tag and injects an alert, confirming arbitrary JavaScript execution in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Ricoh Web Image Monitor 2.03
No auth needed
Prerequisites: Victim must visit a crafted URL or the attacker must trick the victim into clicking a malicious link
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026