EIP-2026-112392
PRE-CVESpitfire 1.0.381 - Cross-Site Scripting / Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112392. PoCs published by Nijel the Destroyer.
AI-analyzed exploit summary The provided code demonstrates a cross-site scripting (XSS) vulnerability in Spitfire CMS by injecting a malicious script via the 'search' parameter in the URL. This exploit can execute arbitrary JavaScript in the context of the affected site, potentially leading to cookie theft or other client-side attacks.
Description
Spitfire 1.0.381 - Cross-Site Scripting / Cross-Site Request Forgery
Exploits (1)
The provided code demonstrates a cross-site scripting (XSS) vulnerability in Spitfire CMS by injecting a malicious script via the 'search' parameter in the URL. This exploit can execute arbitrary JavaScript in the context of the affected site, potentially leading to cookie theft or other client-side attacks.