Description
Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not automatically URL encode parameters were still vulnerable.
Remediation
References
Related Vulnerabilities
Drupal Improper Access Control Vulnerability (CVE-2016-5385)
WebLogic Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10334)
MongoDb Improper Input Validation Vulnerability (CVE-2012-6619)
SharePoint CVE-2018-8161 Vulnerability (CVE-2018-8161)
WordPress Plugin Custom Search by BestWebSoft Unspecified Vulnerability (1.21)