Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.
| Software | From | Fixed in |
|---|---|---|
| revive-adserver / revive_adserver | 5.3.0-rc1 | 5.3.0-rc1.x |
| revive-adserver / revive_adserver | - | 5.3.0 |