EIP-2026-112801

PRE-CVE

TSguestbook 2.1 - 'Message' HTML Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112801. PoCs published by Trash-80.

AI-analyzed exploit summary This is a functional proof-of-concept for an HTML injection vulnerability in TSguestbook. The exploit demonstrates how an attacker can inject malicious JavaScript code into the 'message' field, leading to arbitrary code execution in the context of a user's browser.

Description

TSguestbook 2.1 - 'Message' HTML Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by Trash-80 · textwebappsphp
https://www.exploit-db.com/exploits/23084

This is a functional proof-of-concept for an HTML injection vulnerability in TSguestbook. The exploit demonstrates how an attacker can inject malicious JavaScript code into the 'message' field, leading to arbitrary code execution in the context of a user's browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: TSguestbook
No auth needed
Prerequisites: Access to the guestbook submission form
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026