EIP-2026-114634

PRE-CVE

Zomplog 3.9 - 'message' Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114634. PoCs published by 10n1z3d.

AI-analyzed exploit summary The exploit demonstrates multiple reflected XSS vulnerabilities in Zomplog 3.9 by injecting arbitrary JavaScript via the 'message' parameter in various admin endpoints. The PoC uses simple script tags to trigger an alert with the victim's cookies, confirming the vulnerability.

Description

Zomplog 3.9 - 'message' Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by 10n1z3d · textwebappsphp
https://www.exploit-db.com/exploits/34476

The exploit demonstrates multiple reflected XSS vulnerabilities in Zomplog 3.9 by injecting arbitrary JavaScript via the 'message' parameter in various admin endpoints. The PoC uses simple script tags to trigger an alert with the victim's cookies, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Zomplog 3.9
Auth required
Prerequisites: Access to admin endpoints · Victim interaction required
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026