PoC Index

CVE-2019-5433

MEDIUM 5.8EPSS 1.7%

A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks. This vulnerability was addressed in version 4.2.0.

CVSS v3.0
5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.68% chance of exploitation in the next 30 days, 75th percentile
Published
2019-05-06
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related