code-projects Online Reviewer System 1.0 contains a cross-site scripting (XSS) vulnerability in an unspecified function within /system/system/admins/manage/users/btn_functions.php. The issue is triggered by manipulation of the firstname argument, which is not properly sanitized/encoded before being reflected/used in a web context, allowing an attacker to inject and execute arbitrary script in a victim’s browser. The attack is remotely exploitable and a public exploit is available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept demonstration for CVE-2026-2222, described as an MQTT broker CONNECT packet heap overflow. It contains four files: a LICENSE, a README with vulnerability description and build/run instructions, a minimal Python script (exploit_mqtt.py), and a C program (mqtt_broker_sim.c) that simulates the vulnerable broker logic. The core exploit logic is in mqtt_broker_sim.c. The function process_connect() misparses the MQTT Remaining Length field by reading packet[1:3] as a 16-bit integer instead of using MQTT variable-length decoding. It then allocates a heap buffer of that size and blindly memcpy()s that many bytes from packet+3 without checking whether the packet actually contains that much data. The included main() function constructs a malicious packet with bytes 0x10 0xFF 0xFF ... so the broker interprets the remaining length as 65535 while the actual packet is only 9 bytes long, causing an out-of-bounds read/write scenario and heap overflow in the simulated context. The Python file is not a functional network exploit. It imports socket but does not connect to any host or send any packet; it only prints a message instructing the user to run the local broker simulation. Therefore, despite the README describing remote code execution potential against a broker, the repository itself only provides a local demonstration of vulnerable parsing logic rather than a complete remote exploit against a real MQTT service. No hardcoded IPs, domains, URLs, ports, registry keys, or live network endpoints are present in the code. The only concrete observable endpoints are local file paths and the protocol-level target concept of an MQTT CONNECT packet. Overall, this is a non-framework, educational POC repository showing how malformed MQTT CONNECT length handling could lead to heap corruption.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.