CVE-2021-22871
26.01.2021, 18:16
Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.
Vendor | Product | Version |
---|---|---|
revive-adserver | revive_adserver | 𝑥 < 5.1.0 |
𝑥
= Vulnerable software versions
References