EIP-2026-113356
PRE-CVEWebsiteBaker Addon Concert Calendar 2.1.4 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113356. PoCs published by Stefan Schurtz.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in Websitebaker Add-on 'Concert Calendar 2.1.4'. The SQLi occurs due to unsanitized user input in the 'date' parameter, while the XSS is triggered by reflecting the same parameter without proper encoding.
Description
WebsiteBaker Addon Concert Calendar 2.1.4 - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in Websitebaker Add-on 'Concert Calendar 2.1.4'. The SQLi occurs due to unsanitized user input in the 'date' parameter, while the XSS is triggered by reflecting the same parameter without proper encoding.