Home
LOW: 3.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N 6 (semver)
affected
5 (semver)
affected
6.0.2 (semver)
unaffected
5.5.3 (semver)
unaffected
Description
Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.
Product status
5 (semver)
6.0.2 (semver)
5.5.3 (semver)
References
hackerone.com/reports/3404968