Description
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.
Remediation
References
Related Vulnerabilities
MySQL CVE-2021-2356 Vulnerability (CVE-2021-2356)
MySQL CVE-2019-2585 Vulnerability (CVE-2019-2585)
Oracle Database Server Improper Input Validation Vulnerability (CVE-2018-1000873)
WordPress Plugin Custom Menu Cross-Site Scripting (1.3.3)
Oracle JRE Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10356)