Medium severity6.1NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2021-22872
CVE-2021-22872
Description
Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not automatically URL encode parameters were still vulnerable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*range: <5.1.0
- (no CPE)range: <5.1.0
- Revive Adserver/Revive Adserverdescription
Patches
Vulnerability mechanics
References
6- github.com/revive-adserver/revive-adserver/commit/00fdb8d0envdPatchThird Party Advisory
- github.com/revive-adserver/revive-adserver/commit/1dbcf7d50nvdPatchThird Party Advisory
- hackerone.com/reports/986365nvdExploitThird Party Advisory
- packetstormsecurity.com/files/161070/Revive-Adserver-5.0.5-Cross-Site-Scripting-Open-Redirect.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2021/Jan/60nvdBroken LinkMailing ListThird Party Advisory
- www.revive-adserver.com/security/revive-sa-2021-001/nvdVendor Advisory
News mentions
0No linked articles in our index yet.