EIP-2026-111884
PRE-CVESamTodo 1.1 - 'completed' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111884. PoCs published by David Sopas Ferreira.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in SamTodo 1.1 by injecting malicious script tags via the 'completed' parameter in the URL. The payload bypasses input sanitization and executes arbitrary HTML/JavaScript in the context of the affected site.
Description
SamTodo 1.1 - 'completed' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in SamTodo 1.1 by injecting malicious script tags via the 'completed' parameter in the URL. The payload bypasses input sanitization and executes arbitrary HTML/JavaScript in the context of the affected site.