Loading
Generated remediation guidance and an executive summary. No account required.
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
Use CWE-384, Revive-Adserver vendor hub and Revive Adserver product page to widen CVE-2017-5831 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-48986, CVE-2025-52664 and CVE-2025-52670 for nearby disclosures in the same product family.