Open Redirect Vulnerability in Revive Adserver by Revive
CVE-2021-22873
Key Information:
- Vendor
Revive-adserver
- Vendor
- CVE Published:
- 26 January 2021
Badges
What is CVE-2021-22873?
Revive Adserver, prior to version 5.1.0, has an open redirect vulnerability affecting the ‘dest’, ‘oadest’, and ‘ct0’ parameters in the lg.php and ck.php delivery scripts. This flaw was originally intended to allow third-party ad servers to track delivery metrics; however, due to changes in tracking methodologies, this functionality has now been deemed insecure. The ability for attackers to exploit these redirects poses a risk, enabling them to divert users to potentially harmful sites, which can compromise user security and trust.
Affected Version(s)
https://github.com/revive-adserver/revive-adserver Fixed in 5.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
71% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
