ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2016-9130
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists requiring a trusted (non-admin) account. The website name wasn39t properly escaped when displayed in the campaign-zone.php script.