cve/2021/CVE-2021-22871.md
2025-09-29 21:09:30 +02:00

943 B

CVE-2021-22871

Description

Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.

POC

Reference

Github

No PoCs found on GitHub currently.