Description
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the banner related pages.
Remediation
References
Related Vulnerabilities
ProjectSend Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-11378)
WordPress Plugin Testimonial Slider Cross-Site Scripting (1.2.1)
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2019-15635)
MODX Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-7321)