Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not automatically URL encode parameters were still vulnerable.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2021-01-21T19:15:02

Updated: 2021-01-25T16:06:20

Reserved: 2021-01-06T00:00:00


Link: CVE-2021-22872

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-01-26T18:16:19.100

Modified: 2021-02-02T19:59:16.663


Link: CVE-2021-22872

JSON object: View

cve-icon Redhat Information

No data.

CWE