EIP-2026-105013

PRE-CVE

Affiliate Pro 1.7 - 'Multiple' Cross Site Scripting (XSS)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105013. PoCs published by Vulnerability-Lab.

AI-analyzed exploit summary This is a detailed technical writeup describing multiple reflected XSS vulnerabilities in Affiliate Pro v1.7, with specific details on vulnerable parameters, request methods, and proof-of-concept payloads. It includes HTTP session logs and vulnerable source code snippets.

Description

Affiliate Pro 1.7 - 'Multiple' Cross Site Scripting (XSS)

Exploits (1)

exploitdb WRITEUP
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/50678

This is a detailed technical writeup describing multiple reflected XSS vulnerabilities in Affiliate Pro v1.7, with specific details on vulnerable parameters, request methods, and proof-of-concept payloads. It includes HTTP session logs and vulnerable source code snippets.

Classification
Writeup 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Affiliate Pro v1.7
No auth needed
Prerequisites: Access to the target application's registration form
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026