A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.maianaffiliate.com/ | vendor advisory |
https://github.com/mari0x00/MaianAffiliate-Code-execution-and-XSS/blob/main/README.md | third party advisory exploit |