Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28377 | The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1). |
Thu, 18 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adform Site Tracking 1.1 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. | The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1). |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 19 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Tue, 19 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adform Site Tracking 1.1 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-18T13:06:53.359Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50891
Updated: 2025-08-19T20:08:09.235Z
Status : Deferred
Published: 2025-08-19T19:15:35.673
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-50891
No data.
OpenCVE Enrichment
No data.
EUVD