EIP-2026-113472
PRE-CVEWonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113472. PoCs published by Sun* Cyber Security Research Team.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in WonderCMS 3.1.3 by uploading a malicious HTML file via the 'uploadFile' functionality. The payload is triggered when accessing the uploaded file, executing arbitrary JavaScript in the context of the victim's browser.
Description
WonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in WonderCMS 3.1.3 by uploading a malicious HTML file via the 'uploadFile' functionality. The payload is triggered when accessing the uploaded file, executing arbitrary JavaScript in the context of the victim's browser.