Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.1

CVE-2021-22873: Revive Adserver before 5.1.0 allows attackers to redirect users

CVE-2021-22873
Summary

Older versions of Revive Adserver have a security flaw that could trick users into visiting fake websites. This is a concern because attackers could use it to steal sensitive information or spread malware. To fix this, update to Revive Adserver 5.1.0 or later.

Original title
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been ava...
Original description
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when delivering ads. However, third party click tracking via redirects is not a viable option anymore, leading to such open redirect functionality being removed and reclassified as a vulnerability.
osv CVSS3.1 6.1
Published: 26 Jan 2021 · Updated: 9 Jul 2026 · First seen: 9 Jul 2026