EIP-2026-112157
PRE-CVESimpli Easy (AFC Simple) NewsLetter 4.2 - Cross-Site Scripting / Information Leakage
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112157. PoCs published by p0deje.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in Simpli Easy Newsletter via the 'do' parameter in cp.php and an information leakage issue where subscriber emails and IPs are stored in a plaintext file (el.txt). Both vulnerabilities are confirmed with proof-of-concept examples.
Description
Simpli Easy (AFC Simple) NewsLetter 4.2 - Cross-Site Scripting / Information Leakage
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in Simpli Easy Newsletter via the 'do' parameter in cp.php and an information leakage issue where subscriber emails and IPs are stored in a plaintext file (el.txt). Both vulnerabilities are confirmed with proof-of-concept examples.