Medium severity5.4NVD Advisory· Published May 6, 2019· Updated Jun 17, 2026
CVE-2019-5433
CVE-2019-5433
Description
A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks. This vulnerability was addressed in version 4.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*range: <4.2.0
- (no CPE)range: >=4.2.0
- (no CPE)range: Fixed version v4.2.0
Patches
Vulnerability mechanics
References
2- www.revive-adserver.com/security/revive-sa-2019-001/nvdPatchVendor Advisory
- hackerone.com/reports/390663nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.