EIP-2026-114621
PRE-CVEZeroBoardXE 1.1.5 (09.01.22) - Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114621. PoCs published by make0day.
AI-analyzed exploit summary The exploit demonstrates a stored XSS vulnerability in ZeroBoardXE 1.1.5 by bypassing the application's input sanitization filters. The PoC uses obfuscated JavaScript in an `<img>` tag's `lowsrc` attribute to execute arbitrary code, leveraging a technique that evades the `removeHackTag` and `removeSrcHack` functions.
Description
ZeroBoardXE 1.1.5 (09.01.22) - Cross-Site Scripting
Exploits (1)
The exploit demonstrates a stored XSS vulnerability in ZeroBoardXE 1.1.5 by bypassing the application's input sanitization filters. The PoC uses obfuscated JavaScript in an `<img>` tag's `lowsrc` attribute to execute arbitrary code, leveraging a technique that evades the `removeHackTag` and `removeSrcHack` functions.