Description
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google Maps v3 Shortcode Cross-Site Scripting (1.2.1)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1488)
WordPress Plugin NextGEN Gallery-WordPress Gallery Information Disclosure (1.9.11)
Sqlite Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-19925)