Description
A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑Side Remote Code Execution
Action: Apply Fix
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw in the p.rfihub.com component of Zeta Marketing Platform version 1.0. Attackers can inject arbitrary JavaScript by crafting a URL that includes a malicious payload in the ca query parameter. The payload runs in the victim’s browser with the same privileges as the page, enabling session hijacking, cookie theft, or phishing attacks.

Affected Systems

Zeta Marketing Platform (ZMP) version 1.0, specifically the p.rfihub.com component. No other vendor or product versions are enumerated as affected.

Risk and Exploitability

The vulnerability allows attackers to execute arbitrary code high‑impact client‑side flaw. Because the attack vector is a URL parameter, it can be easily crafted and distributed via email or social engineering. The EPSS score is < 1%, indicating a low exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting it may not be widely exploited yet, but the inherent risk of XSS remains high. Exploitation requires only a link click, with no user privilege elevation on the server.

Generated by OpenCVE AI on September 21, 2026 at 05:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Sanitize and validate the ca parameter to ensure scripts are not reflected in the response.
  • Enforce a Content Security Policy that blocks inline script execution and restricts script origins.
  • Upgrade Zeta Marketing Platform to the latest version once a vendor‑issued patch addressing the reflected XSS is released.

Generated by OpenCVE AI on September 21, 2026 at 05:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Reflected XSS in Zeta Marketing Platform's p.rfihub.com Component

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Zetamarketingplatform
Zetamarketingplatform zmp
Vendors & Products Zetamarketingplatform
Zetamarketingplatform zmp

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.
References

Subscriptions

Zetamarketingplatform Zmp
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T15:21:32.092Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79035

cve-icon Vulnrichment

Updated: 2026-09-15T15:21:25.953Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T20:18:53.907

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:15:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')