First published: Thu Jan 28 2021(Updated: )
Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Revive-adserver Revive Adserver | <5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22875 is a reflected XSS vulnerability in Revive Adserver before version 5.1.1.
CVE-2021-22875 allows an attacker to execute malicious scripts in the context of a user's browser when the `setPerPage` parameter is manipulated in the `stats.php` file.
The severity of CVE-2021-22875 is medium, with a severity value of 6.1.
To fix CVE-2021-22875, upgrade Revive Adserver to version 5.1.1 or newer.
More information about CVE-2021-22875 can be found in the reference links provided: [GitHub commit](https://github.com/revive-adserver/revive-adserver/commit/6f46076a), [HackerOne report](https://hackerone.com/reports/1083376), and [Revive Adserver security advisory](https://www.revive-adserver.com/security/revive-sa-2021-002/).