MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate main page for all authenticated and unauthenticated visitors.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T02:06:42.612Z

Reserved: 2021-08-23T00:00:00

Link: CVE-2021-39402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-20T15:15:08.940

Modified: 2024-11-21T06:19:28.790

Link: CVE-2021-39402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.