CVE-2026-79035
Deferred Deferred - Pending Action

Reflected XSS in Zeta Marketing Platform via p.rfihub.com

Vulnerability report for CVE-2026-79035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-22

Assigner: MITRE

Description

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-22
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zeta_marketing_platform zmp 1.0
zeta_global zeta_marketing_platform 1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-79035 is a reflected cross-site scripting (XSS) vulnerability in Zeta Marketing Platform (ZMP) v1.0. It exists in the 'ca' parameter of the p.rfihub.com component, which is used for programmatic advertising. The server returns user input in the 'ca' parameter without proper validation or encoding, allowing attackers to inject malicious JavaScript via a crafted URL.

Detection Guidance

To detect this reflected XSS vulnerability, monitor network traffic for requests to p.rfihub.com with the 'ca' parameter containing suspicious payloads. Use tools like Burp Suite or OWASP ZAP to intercept and inspect GET requests for the 'ca' parameter. Check server responses for reflected input without proper encoding.

Impact Analysis

This vulnerability can lead to session hijacking by stealing cookies or session tokens, phishing attacks where users are tricked into submitting sensitive data, defacement of web pages, or malware delivery by redirecting users to malicious downloads. Attackers exploit it by convincing victims to click a specially crafted link.

Compliance Impact

This vulnerability could lead to data breaches, unauthorized access to user data, or exposure of sensitive information, which may violate GDPR and HIPAA compliance requirements. Organizations using ZMP v1.0 may face legal and regulatory penalties due to insufficient protection against XSS attacks.

Mitigation Strategies

Implement input validation to restrict the 'ca' parameter to expected values. Apply HTML/JS sanitizers to user input and use context-aware HTML encoding before displaying it. Deploy a Content Security Policy (CSP) to block untrusted script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart