ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-22871 - Vulnerability Database

ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-22871

Medium
Reference: CVE-2021-22871
Title: ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property which is then displayed unsanitized in the affiliate-preview.php tag generation screen leading to a persistent cross-site scripting (XSS) vulnerability.