Description
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the banner related pages.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-10260 | Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the banner related pages. |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-06T02:50:38.507Z
Reserved: 2016-11-19T00:00:00.000Z
Link: CVE-2016-9454
No data.
Status : Deferred
Published: 2017-03-28T02:59:00.590
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-9454
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD