First published: Thu Jan 21 2021(Updated: )
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Revive-adserver Revive Adserver | <5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-22871.
The severity of CVE-2021-22871 is medium with a severity value of 4.8.
Revive Adserver versions up to exclusive 5.1.0 are affected by CVE-2021-22871.
CVE-2021-22871 allows any user with a manager account to store potentially malicious content, leading to a persistent cross-site scripting (XSS) vulnerability.
To fix CVE-2021-22871, upgrade to Revive Adserver version 5.1.0 or higher.