Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Tengku Zahasman

#49780de 56,330
5.4CVSS total
Vulnerabilidades · 1
PT-2017-9963
5.4
2017-03-28
Revive Adserver · Revive Adserver · CVE-2016-9126
**Name of the Vulnerable Software and Affected Versions** Revive Adserver versions prior to 3.2.3 **Description** The issue arises from improper escaping of usernames in the audit trail widget of the dashboard upon login, allowing for persistent XSS attacks. An authenticated user with sufficient privileges to create other users could exploit this to access the administrator account. **Recommendations** For versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the audit trail widget in the dashboard until the update is applied. Additionally, limit the creation of new users to trusted individuals to minimize the risk of exploitation.