EIP-2026-119455

PRE-CVE

Zoho BugTracker - Multiple Persistent Cross-Site Scripting Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119455. PoCs published by LiquidWorm.

AI-analyzed exploit summary This HTML/JavaScript PoC demonstrates stored XSS vulnerabilities in Zoho BugTracker by submitting crafted input to the 'comment' and 'mystatus' parameters via POST requests. The exploit triggers arbitrary script execution in the context of the user's browser session.

Description

Zoho BugTracker - Multiple Persistent Cross-Site Scripting Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappswindows
https://www.exploit-db.com/exploits/20320

This HTML/JavaScript PoC demonstrates stored XSS vulnerabilities in Zoho BugTracker by submitting crafted input to the 'comment' and 'mystatus' parameters via POST requests. The exploit triggers arbitrary script execution in the context of the user's browser session.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Zoho BugTracker (version not specified)
Auth required
Prerequisites: Access to a valid Zoho BugTracker session · Knowledge of target project and issue IDs
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026