EIP-2026-113170
PRE-CVEw2wiki - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113170. PoCs published by HaHwul.
AI-analyzed exploit summary The exploit demonstrates two XSS vulnerabilities in w2wiki: a stored XSS via a crafted POST request to save a malicious page, and a reflected XSS via manipulated URL parameters in edit and search actions. Both payloads use an img tag with an onerror event to trigger JavaScript execution.
Description
w2wiki - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates two XSS vulnerabilities in w2wiki: a stored XSS via a crafted POST request to save a malicious page, and a reflected XSS via manipulated URL parameters in edit and search actions. Both payloads use an img tag with an onerror event to trigger JavaScript execution.