Description
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session.
Remediation
References
Related Vulnerabilities
WordPress Plugin Venture Event Manager Cross-Site Scripting (3.2.4)
WordPress Plugin Query Interface Security Bypass (1.1)
WordPress Plugin WP SMS Cross-Site Scripting (5.4.9)
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2021-43948)
WordPress Plugin Author Chat Unspecified Vulnerability (1.9.0)