CVE Database
/

CVE-2021-22889

Back to search

CVE-2021-22889

Published: Mar 25, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and pressing a certain key combination to execute injected JavaScript code.

VendorProductVersions

n/a

https://github.com/revive-adserver/revive-adserver

affected
Fixed in v5.2.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now