CVE-2020-8143

CVE-2020-8143

Vendor N/A
Product https://github.com/revive-adserver/revive-adserver
Weakness CWE-601 · Open redirect
Published April 3, 2020
Last update August 4, 2024

CVSS base score

What the vulnerability does

01Description

An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the “/www/admin/*-modify.php” could be skipped if no meaningful parameter was sent. No action was performed, but the user was still redirected to the target page, specified via the “returnurl” GET parameter.

Key dates

02Disclosure timeline

April 3, 2020 CVE published
August 4, 2024 Record updated

Related vulnerabilities

04Related CVE