Description
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2020-2778 Vulnerability (CVE-2020-2778)
WebLogic Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-1000180)
WordPress Plugin Brute Force Login Protection Unspecified Vulnerability (1.5)
Lighttpd Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2022-41556)