PT-2021-15246 · Unknown · Revive Adserver

Mbeccati

·

Published

2021-01-21

·

Updated

2021-02-02

·

CVE-2021-22873

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 5.1.0
Description The issue allows for open redirects via the dest, oadest, and/or ct0 parameters of the "lg.php" and "ck.php" delivery scripts. This functionality was previously available by design to enable third-party ad servers to track metrics when delivering ads. However, with third-party click tracking via redirects no longer being a viable option, this open redirect functionality has been removed and is now considered a vulnerability.
Recommendations For versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the lg.php and ck.php delivery scripts to minimize the risk of exploitation. Avoid using the dest, oadest, and ct0 parameters in these scripts until the issue is resolved.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22873

Affected Products

Revive Adserver