EIP-2026-111973
PRE-CVESelectaPix 1.4.1 - 'uploadername' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111973. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This is a functional proof-of-concept for a stored XSS vulnerability in SelectaPix 1.4.1. The exploit demonstrates how an attacker can inject malicious JavaScript into the 'uploadername' parameter, which executes in the context of the victim's browser when the form is submitted.
Description
SelectaPix 1.4.1 - 'uploadername' Cross-Site Scripting
Exploits (1)
This is a functional proof-of-concept for a stored XSS vulnerability in SelectaPix 1.4.1. The exploit demonstrates how an attacker can inject malicious JavaScript into the 'uploadername' parameter, which executes in the context of the victim's browser when the form is submitted.