EIP-2026-112567
PRE-CVETCExam 11.1.16 - 'user_password' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112567. PoCs published by AutoSec Tools.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in TCExam's user registration page by injecting a malicious script via the 'user_password' parameter. The payload bypasses insufficient input sanitization, allowing arbitrary JavaScript execution in the context of the affected site.
Description
TCExam 11.1.16 - 'user_password' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in TCExam's user registration page by injecting a malicious script via the 'user_password' parameter. The payload bypasses insufficient input sanitization, allowing arbitrary JavaScript execution in the context of the affected site.