An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the “/www/admin/*-modify.php” could be skipped if no meaningful parameter was sent. No action was performed, but the user was still redirected to the target page, specified via the “returnurl” GET parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2020-04-03T20:52:41
Updated: 2024-08-04T09:48:25.605Z
Reserved: 2020-01-28T00:00:00
Link: CVE-2020-8143
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-03T21:15:12.717
Modified: 2024-11-21T05:38:22.613
Link: CVE-2020-8143
Redhat
No data.