Security readout for executives and security teams
Plain-English summary
MaianAffiliate v1.0 is reported to allow code injection through the admin panel when adding a product. The injected content is then shown on the affiliate main page to both logged-in and public visitors, creating risk to site users and brand trust.
Executive priority
Treat as a targeted web-application risk where MaianAffiliate v1.0 is deployed. Prioritize confirming exposure and controlling admin access, because public visitors may be affected if content is injected through the admin workflow.
Technical view
The source bundle describes an admin-originated code injection issue in MaianAffiliate v1.0 with reflected output on the affiliate main page. No CVSS, CWE, vendor advisory, affected CPE, or patch information is provided in the supplied sources.
Likely exposure
Exposure is likely limited to organizations running MaianAffiliate v1.0 with administrative product-management access. Public-facing affiliate pages may expose visitors to injected content if a malicious or compromised admin account creates a tainted product entry.
Exploitation context
The CVE is not listed as KEV in the source bundle. A public GitHub reference is cited, but the supplied evidence does not establish active exploitation in the wild or provide confirmed exploitation prevalence.
Researcher notes
Evidence is sparse: no CVSS vector, CWE mapping, patch status, or precise affected CPE appears in the bundle. Analysis should stay tied to MaianAffiliate v1.0 and the described add-product admin path.
Mitigation direction
- Inventory systems for MaianAffiliate v1.0 deployments.
- Restrict admin-panel access to trusted users and management networks.
- Check MaianScriptWorld guidance for fixed versions or retirement advice.
- Review product fields for safe input handling and output encoding.
- Remove suspicious product entries and investigate related admin activity.
Validation and detection
- Confirm whether MaianAffiliate v1.0 exists in asset inventory.
- Review admin-created product records for unexpected scripts or markup.
- Inspect affiliate main page rendering for unsanitized product content.
- Check web logs for unusual admin product changes.
- Verify public affiliate pages no longer reflect unsafe product content.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-39402 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.maianscriptworld.co.uk/CVE reference · x_refsource_MISC
- https://github.com/mari0x00/MaianAffiliate-Code-execution-and-XSSCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
