{ "schema_version": "1.4.0", "id": "GHSA-j7g3-qm5c-2j6r", "modified": "2025-04-20T03:34:57Z", "published": "2022-05-13T01:38:32Z", "aliases": [ "CVE-2016-9471" ], "details": "Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when creating users on a Revive Adserver instance. Especially, control characters were not filtered, allowing apparently identical usernames to co-exist in the system, due to the fact that such characters are normally ignored when an HTML page is displayed in a browser. The issue could have therefore been exploited for user spoofing, although elevated privileges are required to create users within Revive Adserver.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-9471" }, { "type": "WEB", "url": "https://github.com/revive-adserver/revive-adserver/commit/05b1eceb" }, { "type": "WEB", "url": "https://hackerone.com/reports/128181" }, { "type": "WEB", "url": "https://www.revive-adserver.com/security/revive-sa-2016-002" } ], "database_specific": { "cwe_ids": [ "CWE-75" ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2017-03-28T02:59:00Z" } }