CVE-2019-5433
Last modified
CVE-2019-5433 is a vulnerability of currently unknown severity. A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks. This vulnerability was addressed in version 4.2.0.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.
Description
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks. This vulnerability was addressed in version 4.2.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Revive-Adserver | Revive Adserver | < 4.2.0 |
References
- https://hackerone.com/reports/390663Exploit, Third Party Advisory
- https://www.revive-adserver.com/security/revive-sa-2019-001/Patch, Vendor Advisory
- https://hackerone.com/reports/390663Exploit, Third Party Advisory
- https://www.revive-adserver.com/security/revive-sa-2019-001/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5433?
How severe is CVE-2019-5433?
How do I fix CVE-2019-5433?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5427c3p0 version < 0.9.5.4 may be exploited by a billion laughs …7.5
- CVE-2019-5428Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5429Untrusted search path in FileZilla before 3.41.0-rc1 allows …7.8
- CVE-2019-5430In UniFi Video 3.10.0 and prior, due to the lack of CSRF pro…
- CVE-2019-5431This vulnerability was caused by an incomplete fix to CVE-20…5.4
- CVE-2019-5432A specifically malformed MQTT Subscribe packet crashes MQTT …7.5
- CVE-2019-5434An attacker could send a specifically crafted payload to the…
- CVE-2019-5435An integer overflow in curl's URL API results in a buffer ov…
- CVE-2019-5436A heap buffer overflow in the TFTP receiving code allows for…7.8
- CVE-2019-5437Information exposure through the directory listing in npm's …
- CVE-2019-5438Path traversal using symlink in npm harp module versions <= …5.3
- CVE-2019-5439A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash…
Are you affected by CVE-2019-5433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
