PT-2017-9963 · Revive Adserver · Revive Adserver
Tengku Zahasman
·
Published
2017-03-28
·
Updated
2019-10-09
·
CVE-2016-9126
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Revive Adserver versions prior to 3.2.3
Description
The issue arises from improper escaping of usernames in the audit trail widget of the dashboard upon login, allowing for persistent XSS attacks. An authenticated user with sufficient privileges to create other users could exploit this to access the administrator account.
Recommendations
For versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the audit trail widget in the dashboard until the update is applied. Additionally, limit the creation of new users to trusted individuals to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Revive Adserver