What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform smdp-affiliate-platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through <= 1.4.8.
Explanation of Vulnerability in Simple Terms
02Summary
Affiliate Platform versions up to 1.4.8 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the application. An attacker can craft a malicious link that, when visited by a user, executes arbitrary JavaScript in their browser. This can lead to session hijacking, credential theft, or malware distribution. The vulnerability affects all users who click on attacker-controlled links.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in a user's browser to steal session data, credentials, or redirect to phishing sites.
Potential impact on your site
04Site Impact
Users visiting attacker-controlled links can have their sessions compromised or be redirected to malicious sites; site reputation may suffer.
Conditions required to exploit
05Prerequisites
Attacker must trick a user into clicking a malicious link (no authentication required to craft the payload).
Key dates
06Disclosure timeline
October 29, 2024
CVE published
April 28, 2026
Record updated