EIP-2026-112389
PRE-CVESPIP 2.x - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112389. PoCs published by anonymous.
AI-analyzed exploit summary This is a working PoC for an XSS vulnerability in SPIP's admin panel, leveraging unsanitized input in the 'name' attribute of a hidden input field. It generates an exploit HTML page that submits a crafted POST request to execute arbitrary JavaScript in the context of the target site.
Description
SPIP 2.x - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
This is a working PoC for an XSS vulnerability in SPIP's admin panel, leveraging unsanitized input in the 'name' attribute of a hidden input field. It generates an exploit HTML page that submits a crafted POST request to execute arbitrary JavaScript in the context of the target site.