← Zuruck zu CVEs
CVE-2021-22873
MEDIUM6.1
Beschreibung
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when delivering ads. However, third party click tracking via redirects is not a viable option anymore, leading to such open redirect functionality being removed and reclassified as a vulnerability.
CVE Details
CVSS v3.1 Bewertung6.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht1/26/2021
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
revive-adserver:revive_adserver
Schwachen (CWE)
CWE-601CWE-601
Referenzen
http://packetstormsecurity.com/files/161070/Revive-Adserver-5.0.5-Cross-Site-Scripting-Open-Redirect.html(support@hackerone.com)
http://seclists.org/fulldisclosure/2021/Jan/60(support@hackerone.com)
https://github.com/revive-adserver/revive-adserver/issues/1068(support@hackerone.com)
https://hackerone.com/reports/1081406(support@hackerone.com)
https://www.revive-adserver.com/security/revive-sa-2021-001/(support@hackerone.com)
http://packetstormsecurity.com/files/161070/Revive-Adserver-5.0.5-Cross-Site-Scripting-Open-Redirect.html(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2021/Jan/60(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/revive-adserver/revive-adserver/issues/1068(af854a3a-2127-422b-91ae-364da2661108)
https://hackerone.com/reports/1081406(af854a3a-2127-422b-91ae-364da2661108)
https://www.revive-adserver.com/security/revive-sa-2021-001/(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.