Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time,…
hackerone·CWE-384·Published 2017-03-28