ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2016-9454 - Vulnerability Database

ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2016-9454

Medium
Reference: CVE-2016-9454
Title: ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists requiring a trusted (non-admin) account. The banner image URL for external banners wasn39t properly escaped when displayed in most of the banner related pages.