PT-2017-9964 · Revive Adserver · Revive Adserver

Published

2017-03-28

·

Updated

2019-10-09

·

CVE-2016-9127

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 3.2.3
Description The password recovery form in Revive Adserver is susceptible to Cross-Site Request Forgery (CSRF) attacks. This issue could be exploited to send a large number of password recovery emails to registered users.
Recommendations For versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the password recovery form to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9127

Affected Products

Revive Adserver