Description
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
ownCloud Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-1850)
Oracle Database Server CVE-2013-5858 Vulnerability (CVE-2013-5858)
WordPress Plugin ProfileGrid-User Profiles, Groups and Communities Cross-Site Scripting (2.6.6)
Artifactory Improper Privilege Management Vulnerability (CVE-2022-0668)