EIP-2026-112735
PRE-CVEToko Lite CMS 1.5.2 - HTTP Response Splitting / Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112735. PoCs published by Gjoko Krstic.
AI-analyzed exploit summary The exploit demonstrates an HTTP response splitting vulnerability and multiple XSS vulnerabilities in Toko LiteCMS 1.5.2 due to improper input sanitization. The PoC includes a crafted HTML form to trigger XSS via POST parameters and highlights insecure header manipulation in edit.php.
Description
Toko Lite CMS 1.5.2 - HTTP Response Splitting / Cross-Site Scripting
Exploits (1)
The exploit demonstrates an HTTP response splitting vulnerability and multiple XSS vulnerabilities in Toko LiteCMS 1.5.2 due to improper input sanitization. The PoC includes a crafted HTML form to trigger XSS via POST parameters and highlights insecure header manipulation in edit.php.