CVE Database
/

CVE-2016-9127

Back to search

CVE-2016-9127

Published: Mar 28, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of password recovery emails to the registered users, especially in conjunction with a bug that caused recovery emails to be sent to all the users at once. Both issues have been fixed.

VendorProductVersions

n/a

Revive Adserver All versions before 3.2.3

affected
Revive Adserver All versions before 3.2.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now