Impact
The vulnerability resides in the checkForPostRequests method of application/core/MY_Controller.php used by the Subscribed Emails Admin component. A maliciously crafted User‑Agent header is not properly arbitrary JavaScript that is rendered when an administrator accesses the admin page. This constitutes a cross‑site scripting flaw (CWE‑79) that enables code execution in the context of the admin user.
Affected Systems
Any deployment of the kirilkirkov Ecommerce‑CodeIgniter‑Bootstrap application that includes the Subscribed Emails Admin module and was built from a commit preceding 23105f25dadf57b4314fc015a63a7c6e910c89df (up to commit 213babdbaa949e94557246414db0130e01394517) is vulnerable. Because the product adopts a rolling‑release model, specific version information for affected or updated releases is not disclosed; an instance that has not applied the patch commit remains susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1 %, implying that the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, inferred from the additional exploitation steps. A publicly available exploit demonstrates that the flaw can be leveraged from a simple HTTP request.
OpenCVE Enrichment