CVE-2021-22888: XSS
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the status parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22888?
CVE-2021-22888 is a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php in Revive Adserver before v5.2.0.
How does CVE-2021-22888 impact Revive Adserver?
CVE-2021-22888 allows an attacker to execute injected JavaScript by tricking a user into clicking on a specially crafted URL.
What is the severity of CVE-2021-22888?
CVE-2021-22888 has a severity rating of medium with a CVSS score of 6.1.
Which version of Revive Adserver is affected by CVE-2021-22888?
Revive Adserver versions before v5.2.0 are affected by CVE-2021-22888.
How can I fix CVE-2021-22888?
To fix CVE-2021-22888, you should upgrade to Revive Adserver v5.2.0 or later.