CVE-2021-22871: XSS
Published Jan 21, 2021
·Updated
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Affected Software
1 affected component
revive-adserver Revive Adserver<5.1.0
Remediation
Event History
Jan 21, 2021
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-22871.
2
What is the severity of CVE-2021-22871?
The severity of CVE-2021-22871 is medium with a severity value of 4.8.
3
What software versions are affected by CVE-2021-22871?
Revive Adserver versions up to exclusive 5.1.0 are affected by CVE-2021-22871.
4
What is the impact of CVE-2021-22871?
CVE-2021-22871 allows any user with a manager account to store potentially malicious content, leading to a persistent cross-site scripting (XSS) vulnerability.
5
How can I fix CVE-2021-22871?
To fix CVE-2021-22871, upgrade to Revive Adserver version 5.1.0 or higher.