Unrated severityNVD Advisory· Published Mar 25, 2021· Updated Aug 3, 2024
CVE-2021-22889
CVE-2021-22889
Description
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the statsBreakdown parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and pressing a certain key combination to execute injected JavaScript code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Revive Adserver/Revive Adserverdescription
- Range: <5.2.0
Patches
Vulnerability mechanics
References
3- github.com/revive-adserver/revive-adserver/commit/2f868414mitrex_refsource_MISC
- hackerone.com/reports/1097217mitrex_refsource_MISC
- www.revive-adserver.com/security/revive-sa-2021-003/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.