CVE-2021-22873
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 69.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when delivering ads. However, third party click tracking via redirects is not a viable option anymore, leading to such open redirect functionality being removed and reclassified as a vulnerability.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 69.56% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- revive-adserver/revive adserver
- Source
- support@hackerone.com
References
- http://packetstormsecurity.com/files/161070/Revive-Adserver-5.0.5-Cross-Site-Scripting-Open-Redirect.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Jan/60Broken Link, Mailing List, Third Party Advisory
- https://github.com/revive-adserver/revive-adserver/issues/1068Issue Tracking, Third Party Advisory
- https://hackerone.com/reports/1081406Exploit, Third Party Advisory
- https://www.revive-adserver.com/security/revive-sa-2021-001/Vendor Advisory
- http://packetstormsecurity.com/files/161070/Revive-Adserver-5.0.5-Cross-Site-Scripting-Open-Redirect.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Jan/60Broken Link, Mailing List, Third Party Advisory
- https://github.com/revive-adserver/revive-adserver/issues/1068Issue Tracking, Third Party Advisory
- https://hackerone.com/reports/1081406Exploit, Third Party Advisory
- https://www.revive-adserver.com/security/revive-sa-2021-001/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.