Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
| Software | From | Fixed in |
|---|---|---|
| revive-adserver / revive_adserver | - | 5.1.0 |