Impact
The vulnerability is a reflected cross‑site scripting flaw in the p.rfihub.com component of Zeta Marketing Platform version 1.0. Attackers can inject arbitrary JavaScript by crafting a URL that includes a malicious payload in the ca query parameter. The payload runs in the victim’s browser with the same privileges as the page, enabling session hijacking, cookie theft, or phishing attacks.
Affected Systems
Zeta Marketing Platform (ZMP) version 1.0, specifically the p.rfihub.com component. No other vendor or product versions are enumerated as affected.
Risk and Exploitability
The vulnerability allows attackers to execute arbitrary code high‑impact client‑side flaw. Because the attack vector is a URL parameter, it can be easily crafted and distributed via email or social engineering. The EPSS score is < 1%, indicating a low exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting it may not be widely exploited yet, but the inherent risk of XSS remains high. Exploitation requires only a link click, with no user privilege elevation on the server.
OpenCVE Enrichment