Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Revive_adserver | Revive-adserver | * | 5.5.2 (including) |
| Revive_adserver | Revive-adserver | 6.0.0 (including) | 6.0.1 (including) |