PT-2015-7529 · Revive Adserver · Revive Adserver

N B Sri Harsha

·

Published

2015-10-14

·

Updated

2018-10-09

·

CVE-2015-7366

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 3.2.2
Description The issue allows remote attackers to hijack user authentication for certain requests, potentially causing a denial of service or modifying user account details. This can be achieved via crafted POST requests to specific scripts, such as account-user-*.php, allowing attackers to perform actions like changing the contact name and language.
Recommendations For versions prior to 3.2.2, update to version 3.2.2 or later to resolve the issue.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7366

Affected Products

Revive Adserver