Description
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
Magento Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-9690)
WordPress Plugin WP-Forum Multiple SQL Injection Vulnerabilities (2.3)
WordPress Plugin Booster for WooCommerce Multiple Cross-Site Scripting Vulnerabilities (5.4.8)
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5485)