First published: Thu Jan 28 2021(Updated: )
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Revive-adserver Revive Adserver | <5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2021-22874.
The severity of CVE-2021-22874 is medium (6.1).
The affected software version is Revive Adserver before 5.1.1.
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.
To fix the vulnerability, you should update your Revive Adserver installation to version 5.1.1 or newer.