Description
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
PHP Incorrect Conversion between Numeric Types Vulnerability (CVE-2016-3074)
Nginx Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0337)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-0796)
WordPress Plugin Live Chat with Facebook Messenger Cross-Site Scripting (1.4.4)