Reflected XSS Vulnerability in Revive Adserver by Revive Software
CVE-2020-8115

6.1MEDIUM

What is CVE-2020-8115?

A reflected Cross-Site Scripting (XSS) vulnerability exists within the public afr.php delivery script of Revive Adserver versions up to 5.0.3. The flaw arises from improper handling of user input, allowing attackers to inject malicious JavaScript code that gets executed in the browser of unsuspecting victims. Although the session identifier is stored in an http-only cookie from version 3.2.2 onwards, earlier versions could potentially be exploited under specific conditions, leading to unauthorized access to admin interfaces. This vulnerability underscores the critical need for developers to implement robust input sanitization and validation mechanisms.

Affected Version(s)

https://github.com/revive-adserver/revive-adserver Fixed version v5.0.4

References

EPSS Score

55% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.