Description
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of password recovery emails to the registered users, especially in conjunction with a bug that caused recovery emails to be sent to all the users at once. Both issues have been fixed.
Remediation
References
Related Vulnerabilities
Envoy Proxy CVE-2023-27488 Vulnerability (CVE-2023-27488)
WordPress Plugin Duplicator-WordPress Migration Cross-Site Scripting (1.2.32)
Serendipity Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-5475)
WordPress Plugin YITH WooCommerce Social Login Security Bypass (1.3.4)
WordPress Plugin Delete All Comments Cross-Site Request Forgery (1.0)