First published: Wed Oct 14 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in a banner.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Revive Adserver | <=3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7373 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2015-7373, upgrade to Revive Adserver version 3.2.2 or later where the vulnerability has been addressed.
The impact of CVE-2015-7373 allows remote attackers to inject harmful scripts through a manipulated GET parameter.
All versions of Revive Adserver prior to 3.2.2 are vulnerable to CVE-2015-7373.
The vulnerability in CVE-2015-7373 exists in the "magic-macros" feature of Revive Adserver.