
mari0x00/MaianAffiliate-Code-execution-and-XSS
Releases0
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 5.4 MEDIUM | 3.5 LOW | ||
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel. | |||
| 4.8 MEDIUM | 3.5 LOW | ||
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel. | |||
| 4.8 MEDIUM | 3.5 LOW | ||
MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database. | |||
| 7.2 HIGH | 6.5 MEDIUM | ||
MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate main page for all authenticated and unauthenticated visitors. | |||