EIP-2026-112606
PRE-CVETestLink 1.8.5 - 'order_by_login_dir' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112606. PoCs published by Prashant Khandelwal.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in TestLink 1.8.5 by injecting malicious JavaScript into the 'order_by_login_dir' parameter. The payload triggers an alert dialog, proving arbitrary script execution in the context of the affected site.
Description
TestLink 1.8.5 - 'order_by_login_dir' Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in TestLink 1.8.5 by injecting malicious JavaScript into the 'order_by_login_dir' parameter. The payload triggers an alert dialog, proving arbitrary script execution in the context of the affected site.