EIP-2026-114458
PRE-CVEXoops 2.2.3 - 'search.php' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114458. PoCs published by b0rizQ.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Xoops by injecting malicious JavaScript code via unsanitized user input in the search.php module. The payload executes arbitrary script code in the context of the affected site, potentially stealing cookie-based authentication credentials.
Description
Xoops 2.2.3 - 'search.php' Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Xoops by injecting malicious JavaScript code via unsanitized user input in the search.php module. The payload executes arbitrary script code in the context of the affected site, potentially stealing cookie-based authentication credentials.