PT-2019-17665 · Revive Adserver · Revive Adserver
Sumni
·
Publicado
2019-05-06
·
Atualizado
2019-10-09
·
CVE-2019-5433
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Revive Adserver versions prior to 4.2.0
Description
A phishing attack could be conducted by tricking a user into clicking a specifically crafted admin account-switch.php URL, potentially leading to credential theft or other phishing attacks.
Recommendations
For versions prior to 4.2.0, update to version 4.2.0 to resolve the issue. As a temporary workaround, consider restricting access to the
account-switch.php page until the update is applied. Avoid clicking on suspicious URLs, especially those that may redirect to unsafe domains.Exploit
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Revive Adserver