PT-2022-11397 · Unknown · Maianaffiliate
Mari0X00
·
Published
2022-06-16
·
Updated
2022-06-27
·
CVE-2021-41420
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MaianAffiliate version 1.0
Description
A stored XSS issue allows an authenticated attacker to execute arbitrary JavaScript code in the context of both authenticated and unauthenticated users through the admin panel.
Recommendations
For MaianAffiliate version 1.0, consider disabling access to the admin panel until a fix is available to prevent exploitation. Restrict the execution of JavaScript code within the admin panel to minimize the risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maianaffiliate