EIP-2026-114638
PRE-CVEZomplog 3.9 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114638. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates three vulnerabilities in Zomplog 3.9: stored XSS via the 'about' parameter in settings_menu.php, reflected XSS via the 'id' parameter in editor_pages.php, and CSRF in users.php. Each PoC includes functional HTML/JavaScript to trigger the vulnerabilities.
Description
Zomplog 3.9 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Exploits (1)
The exploit demonstrates three vulnerabilities in Zomplog 3.9: stored XSS via the 'about' parameter in settings_menu.php, reflected XSS via the 'id' parameter in editor_pages.php, and CSRF in users.php. Each PoC includes functional HTML/JavaScript to trigger the vulnerabilities.