CVE-2017-5832: XSS
Published Mar 3, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.
Affected Software
1 affected component
revive-adserver Revive Adserver<=4.0.0
Remediation
Patch Available
Event History
Mar 3, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5832?
CVE-2017-5832 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2017-5832?
To fix CVE-2017-5832, you should upgrade Revive Adserver to version 4.0.1 or later.
3
Who is affected by CVE-2017-5832?
CVE-2017-5832 affects all versions of Revive Adserver prior to 4.0.1 and specifically impacts authenticated users.
4
What type of vulnerability is CVE-2017-5832?
CVE-2017-5832 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
5
Can CVE-2017-5832 be exploited remotely?
Yes, CVE-2017-5832 can be exploited remotely by authenticated users to execute scripts on the affected application.