CVE-2016-9126

CVE-2016-9126

Vendor N/A
Product Revive Adserver All versions before 3.2.3
Weakness CWE-79 · XSS
Published March 28, 2017
Last update August 6, 2024

CVSS base score

What the vulnerability does

01Description

Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user with enough privileges to create other users could exploit the vulnerability to access the administrator account.

Key dates

02Disclosure timeline

March 28, 2017 CVE published
August 6, 2024 Record updated