PT-2019-17665 · Revive Adserver · Revive Adserver

Sumni

·

Published

2019-05-06

·

Updated

2019-10-09

·

CVE-2019-5433

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 4.2.0
Description A phishing attack could be conducted by tricking a user into clicking a specifically crafted admin account-switch.php URL, potentially leading to credential theft or other phishing attacks.
Recommendations For versions prior to 4.2.0, update to version 4.2.0 to resolve the issue. As a temporary workaround, consider restricting access to the account-switch.php page until the update is applied. Avoid clicking on suspicious URLs, especially those that may redirect to unsafe domains.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5433

Affected Products

Revive Adserver