CVE-2015-7373: XSS
Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in a banner.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7373?
CVE-2015-7373 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How can I fix CVE-2015-7373?
To mitigate CVE-2015-7373, upgrade to Revive Adserver version 3.2.2 or later where the vulnerability has been addressed.
What is the impact of CVE-2015-7373?
The impact of CVE-2015-7373 allows remote attackers to inject harmful scripts through a manipulated GET parameter.
Which versions of Revive Adserver are affected by CVE-2015-7373?
All versions of Revive Adserver prior to 3.2.2 are vulnerable to CVE-2015-7373.
What feature is vulnerable in CVE-2015-7373?
The vulnerability in CVE-2015-7373 exists in the "magic-macros" feature of Revive Adserver.