CVE-2021-22874: XSS
Published Jan 28, 2021
·Updated
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the periodpreset parameter.
Affected Software
1 affected component
revive-adserver Revive Adserver<5.1.1
Remediation
Event History
Jan 28, 2021
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2021-22874.
2
What is the severity of CVE-2021-22874?
The severity of CVE-2021-22874 is medium (6.1).
3
What is the affected software version?
The affected software version is Revive Adserver before 5.1.1.
4
What is the description of this vulnerability?
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.
5
How can I fix the vulnerability?
To fix the vulnerability, you should update your Revive Adserver installation to version 5.1.1 or newer.