The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1).
Metrics
Affected Vendors & Products
References
History
Thu, 18 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adform Site Tracking 1.1 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. | The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1). |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 19 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Tue, 19 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adform Site Tracking 1.1 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-08-19T00:00:00.000Z
Updated: 2025-09-18T13:06:53.359Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50891
Updated: 2025-08-19T20:08:09.235Z
Status : Awaiting Analysis
Published: 2025-08-19T19:15:35.673
Modified: 2025-09-18T13:15:35.793
Link: CVE-2025-50891
No data.