Vulnerabilities > Revive Adserver

DATE CVE VULNERABILITY TITLE RISK
2020-04-03 CVE-2020-8143 Open Redirect vulnerability in Revive-Adserver Revive Adserver
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.
5.8
2020-04-03 CVE-2020-8142 Incorrect Authorization vulnerability in Revive-Adserver Revive Adserver
A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144.
local
low complexity
revive-adserver CWE-863
4.6
2020-02-04 CVE-2020-8115 Cross-Site Scripting vulnerability in Revive-Adserver Revive Adserver
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi.
4.3
2019-05-28 CVE-2019-5440 USE of Cryptographically Weak Pseudo-Random Number Generator (Prng) vulnerability in Revive-Adserver Revive Adserver
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality.
6.8
2019-05-06 CVE-2019-5433 Open Redirect vulnerability in Revive-Adserver Revive Adserver
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks.
5.8
2017-03-28 CVE-2016-9472 Cross-Site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS.
3.5
2017-03-28 CVE-2016-9471 Unspecified vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection.
network
high complexity
revive-adserver
2.1
2017-03-28 CVE-2016-9470 7PK - Security Features vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download.
network
revive-adserver CWE-254
critical
9.3
2017-03-28 CVE-2016-9457 Cross-Site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Reflected XSS.
3.5
2017-03-28 CVE-2016-9456 Cross-Site Request Forgery (CSRF) vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF).
6.8