First published: Thu Mar 25 2021(Updated: )
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Revive-adserver Revive Adserver | <5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22888 is a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php in Revive Adserver before v5.2.0.
CVE-2021-22888 allows an attacker to execute injected JavaScript by tricking a user into clicking on a specially crafted URL.
CVE-2021-22888 has a severity rating of medium with a CVSS score of 6.1.
Revive Adserver versions before v5.2.0 are affected by CVE-2021-22888.
To fix CVE-2021-22888, you should upgrade to Revive Adserver v5.2.0 or later.