Description
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the banner related pages.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2008-0349 Vulnerability (CVE-2008-0349)
MySQL CVE-2019-2830 Vulnerability (CVE-2019-2830)
CubeCart Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3904)
Dot CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-3189)
WordPress Plugin WordPress Survey & Poll-Quiz, Survey and Poll SQL Injection (1.1.91)