mari0x00/MaianAffiliate-Code-execution-and-XSS

mari0x00/MaianAffiliate-Code-execution-and-XSS

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM3.5 LOW

A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.

4.8 MEDIUM3.5 LOW

A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.

4.8 MEDIUM3.5 LOW

MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database.

7.2 HIGH6.5 MEDIUM

MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate main page for all authenticated and unauthenticated visitors.