ZeroHour

CVE-2016-9126

CVSS 3.0
5.4 medium
EPSS
1%p72
Published
()
Modified
Description

Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user with enough privileges to create other users could exploit the vulnerability to access the administrator account.

Vendors
revive-adserver
Products
revive adserver
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.