Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user with enough privileges to create other users could exploit the vulnerability to access the administrator account.
References
Link | Resource |
---|---|
https://github.com/revive-adserver/revive-adserver/commit/8d8c6df309ff5fde9dd4770abcd4ec5d2449b3ec | Issue Tracking Patch Third Party Advisory |
https://hackerone.com/reports/97073 | Permissions Required |
https://www.revive-adserver.com/security/revive-sa-2016-001/ | Patch Vendor Advisory |
https://github.com/revive-adserver/revive-adserver/commit/8d8c6df309ff5fde9dd4770abcd4ec5d2449b3ec | Issue Tracking Patch Third Party Advisory |
https://hackerone.com/reports/97073 | Permissions Required |
https://www.revive-adserver.com/security/revive-sa-2016-001/ | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 03:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/revive-adserver/revive-adserver/commit/8d8c6df309ff5fde9dd4770abcd4ec5d2449b3ec - Issue Tracking, Patch, Third Party Advisory | |
References | () https://hackerone.com/reports/97073 - Permissions Required | |
References | () https://www.revive-adserver.com/security/revive-sa-2016-001/ - Patch, Vendor Advisory |
Information
Published : 2017-03-28 02:59
Updated : 2024-11-21 03:00
NVD link : CVE-2016-9126
Mitre link : CVE-2016-9126
CVE.ORG link : CVE-2016-9126
JSON object : View
Products Affected
revive-adserver
- revive_adserver
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')