PT-2020-19953 · Revive Adserver · Revive Adserver

Jacopo Tediosi

·

Published

2020-02-04

·

Updated

2020-02-11

·

CVE-2020-8115

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 5.0.4
Description A reflected XSS issue has been found in the afr.php delivery script. This issue allows an attacker to execute arbitrary JS code on the victim's browser by sending a query string to the "www/delivery/afr.php" script, which is then printed back without proper escaping in a JavaScript context. On older versions, under specific circumstances, it could be possible to steal the session identifier and gain access to the admin interface. However, as of version 3.2.2, the session identifier is stored in an http-only cookie, making it inaccessible.
Recommendations For versions prior to 5.0.4, update to version 5.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the afr.php script to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8115

Affected Products

Revive Adserver