Description
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and pressing a certain key combination to execute injected JavaScript code.
Remediation
References
Related Vulnerabilities
Apache Tomcat Unprotected Transport of Credentials Vulnerability (CVE-2023-28708)
MySQL CVE-2016-0647 Vulnerability (CVE-2016-0647)
WordPress Plugin YITH WooCommerce Wishlist Security Bypass (2.2.13)
WordPress Plugin Admin Font Editor Cross-Site Scripting (1.8)
WordPress Plugin WP Photo Album Plus Cross-Site Scripting (5.0.2)