← back
CVE-2016-9454

CVE-2016-9454

EPSS 1.1%CWE-79
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the banner related pages.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →