ReviveAdserver URL Redirection to Untrusted Site (Open Redirect) Vulnerability - CVE-2020-8143
An Open Redirect vulnerability was discovered in Revive Adserver version lt 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the /www/admin/-modify.php could be skipped if no meaningful parameter was sent. No action was performed but the user was still redirected to the target page specified via the returnurl GET parameter.