Description
Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. Attackers can inject malicious scripts through fullname, username, and email parameters to execute client-side attacks and manipulate browser requests.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
1.7
Credits
Vulnerability-Lab [Research Team]
References
www.vulnerability-lab.com/get_content.php?id=2281
www.vulnerability-lab.com/get_content.php?id=2281 (Vulnerability Lab Advisory)
jdwebdesigner.com/ (Product Homepage)
codecanyon.net/...e-pro-affiliate-management-system/12908496 (Product Homepage)
www.vulncheck.com/...d-cross-site-scripting-via-index-module (VulnCheck Advisory: Affiliate Pro 1.7 Reflected Cross-Site Scripting via Index Module)