Vulnerabilities > Revive Adserver > Revive Adserver > 4.1.0

DATE CVE VULNERABILITY TITLE RISK
2020-04-03 CVE-2020-8142 Incorrect Authorization vulnerability in Revive-Adserver Revive Adserver
A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144.
local
low complexity
revive-adserver CWE-863
4.6
2020-02-04 CVE-2020-8115 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi.
4.3
2019-05-28 CVE-2019-5440 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Revive-Adserver Revive Adserver
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality.
6.8
2019-05-06 CVE-2019-5433 Open Redirect vulnerability in Revive-Adserver Revive Adserver
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks.
5.8