EIP-2026-112943
PRE-CVEVacation Rental 1.8 - Stored Cross-Site Scripting (XSS)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112943. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Vacation Rental 1.8, where malicious payloads can be injected into the 'username', 'title', and 'comment' fields of a property review. The payloads are stored and executed when other users visit the affected property page or reviews section.
Description
Vacation Rental 1.8 - Stored Cross-Site Scripting (XSS)
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Vacation Rental 1.8, where malicious payloads can be injected into the 'username', 'title', and 'comment' fields of a property review. The payloads are stored and executed when other users visit the affected property page or reviews section.