VYPR

Maianaffiliate

by Maianmedia

CVEs (3)

  • CVE-2021-39402HigSep 20, 2021
    risk 0.47cvss 7.2epss 0.01

    MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate main page for all authenticated and unauthenticated visitors.

  • CVE-2021-41420MedJun 16, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.

  • CVE-2021-41421MedJun 16, 2022
    risk 0.31cvss 4.8epss 0.00

    A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.

VYPR — Vulnerability Intelligence