EIP-2026-114468
PRE-CVEXOOPS 2.x - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114468. PoCs published by Aung Khant.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in XOOPS 2.5.0 by injecting malicious scripts into various parameters (module, module[], memberslist_id[], newname[], oldname[]). The PoC includes crafted HTTP requests with payloads that trigger alert popups, confirming the vulnerability.
Description
XOOPS 2.x - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in XOOPS 2.5.0 by injecting malicious scripts into various parameters (module, module[], memberslist_id[], newname[], oldname[]). The PoC includes crafted HTTP requests with payloads that trigger alert popups, confirming the vulnerability.