EIP-2026-114559
PRE-CVEYzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114559. PoCs published by En_dust.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in YzmCMS 5.5 by injecting a malicious JavaScript payload into the 'url' parameter of the link addition functionality. The PoC includes a crafted HTTP POST request that bypasses input filtering and executes arbitrary JavaScript in the context of the application.
Description
YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in YzmCMS 5.5 by injecting a malicious JavaScript payload into the 'url' parameter of the link addition functionality. The PoC includes a crafted HTTP POST request that bypasses input filtering and executes arbitrary JavaScript in the context of the application.