CVE-2021-22875: XSS
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the setPerPage parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22875?
CVE-2021-22875 is a reflected XSS vulnerability in Revive Adserver before version 5.1.1.
How does CVE-2021-22875 affect Revive Adserver?
CVE-2021-22875 allows an attacker to execute malicious scripts in the context of a user's browser when the `setPerPage` parameter is manipulated in the `stats.php` file.
What is the severity of CVE-2021-22875?
The severity of CVE-2021-22875 is medium, with a severity value of 6.1.
How can I fix CVE-2021-22875 in Revive Adserver?
To fix CVE-2021-22875, upgrade Revive Adserver to version 5.1.1 or newer.
Where can I find more information about CVE-2021-22875?
More information about CVE-2021-22875 can be found in the reference links provided: [GitHub commit](https://github.com/revive-adserver/revive-adserver/commit/6f46076a), [HackerOne report](https://hackerone.com/reports/1083376), and [Revive Adserver security advisory](https://www.revive-adserver.com/security/revive-sa-2021-002/).