// For flags

CVE-2020-8142

 

Severity Score

6.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in user to type the current password in order to change the e-mail address or the password. It was however possible for anyone with access to a Revive Adserver admin user interface to bypass such check and change e-email address or password of the currently logged in user by altering the form payload.The attack requires physical access to the user interface of a logged in user. If the POST payload was altered by turning the “pwold” parameter into an array, Revive Adserver would fetch and authorise the operation even if no password was provided.

Una vulnerabilidad de omisión de restricción de seguridad ha sido detectada en Revive Adserver versiones anteriores a 5.0.5, por el usuario hoangn144 de HackerOne. Revive Adserver, como muchas otras aplicaciones, requiere que el usuario registrado escriba la contraseña actual a fin de cambiar la dirección de correo electrónico o la contraseña. Sin embargo, era posible que cualquier persona con acceso a una interfaz de usuario administrador de Revive Adserver omitiera tal comprobación y cambiara la dirección de correo electrónico o la contraseña del usuario registrado actualmente mediante la modificación de la carga útil del formulario. El ataque requiere acceso físico a la interfaz de usuario de usuario registrado. Si la carga útil POST fue alterada al convertir el parámetro "pwold" en una matriz, Revive Adserver buscará y autorizará la operación incluso si ninguna contraseña fue proporcionada.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-28 CVE Reserved
  • 2020-04-03 CVE Published
  • 2023-08-07 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-863: Incorrect Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Revive-adserver
Search vendor "Revive-adserver"
Revive Adserver
Search vendor "Revive-adserver" for product "Revive Adserver"
< 5.0.5
Search vendor "Revive-adserver" for product "Revive Adserver" and version " < 5.0.5"
-
Affected