ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2016-9130 - Vulnerability Database

ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2016-9130

Medium
Reference: CVE-2016-9130
Title: ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists requiring a trusted (non-admin) account. The website name wasn39t properly escaped when displayed in the campaign-zone.php script.