EIP-2026-112263
PRE-CVEsNews 1.7 - 'snews.php' Cross-Site Scripting / HTML Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112263. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in sNews 1.7 by injecting malicious JavaScript into form fields. The PoC submits crafted input to the application, which fails to sanitize user-supplied data, leading to arbitrary script execution in the context of the affected browser.
Description
sNews 1.7 - 'snews.php' Cross-Site Scripting / HTML Injection
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in sNews 1.7 by injecting malicious JavaScript into form fields. The PoC submits crafted input to the application, which fails to sanitize user-supplied data, leading to arbitrary script execution in the context of the affected browser.