Vulnerability record · CVE-2021-22873 · published 26 January 2021
CVE-2021-22873: Revive Adserver open redirect in delivery scripts
Revive Adserver · Revive Adserver
Revive Adserver before 5.1.0 allows open redirects through the dest, oadest, and ct0 parameters of the lg.php and ck.php delivery scripts. The redirect behavior was originally intentional for third-party ad tracking but was removed and reclassified as a vulnerability. It matters because attackers can craft trusted-looking links that send users to arbitrary external sites.
Description
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when delivering ads. However, third party click tracking via redirects is not a viable option anymore, leading to such open redirect functionality being removed and reclassified as a vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw is a medium-severity open redirect requiring user interaction, but high EPSS and public exploit references raise the practical risk of phishing abuse.
What it is
Revive Adserver before 5.1.0 allows open redirects through the dest, oadest, and ct0 parameters of the lg.php and ck.php delivery scripts. The redirect behavior was originally intentional for third-party ad tracking but was removed and reclassified as a vulnerability. It matters because attackers can craft trusted-looking links that send users to arbitrary external sites.
Impact
An attacker can redirect a victim from a legitimate Revive Adserver domain to an attacker-controlled site, enabling phishing, credential theft, or malware delivery under a trusted link. The CVSS vector shows limited confidentiality and integrity impact with no availability impact.
Attack surface
Reachable over the network via crafted URLs to the lg.php and ck.php delivery scripts; no authentication is required, but the victim must click the link (UI:R). The scope is changed because the redirect leaves the vulnerable application's domain.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.696 (99.3rd percentile), and a HackerOne reference is tagged Exploit, indicating public proof-of-concept material exists. No ransomware usage is documented.
What to do
- Upgrade Revive Adserver to 5.1.0 or later, which removes the open redirect functionality.
- If immediate upgrade is not possible, restrict or validate the dest, oadest, and ct0 parameters on lg.php and ck.php to allow only trusted destinations.
- Place the ad server behind a proxy or WAF rule that blocks external redirect targets in those parameters.
- Review and remove any legacy third-party click-tracking redirect configurations that rely on these parameters.
Detection
- Monitor web logs for requests to lg.php or ck.php with dest, oadest, or ct0 parameters containing external URLs or non-allowlisted domains.
- Alert on HTTP 3xx responses from the ad server where the Location header points to a domain outside your organization.
- Correlate outbound clicks from ad server links with subsequent phishing or malware reports from users.
- Search for known exploit payload patterns from the HackerOne and Packet Storm references in proxy or IDS logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/161070/Revive-Adserver-5.0.5-Cross-Site-Scripting-Open-Redirect.html | Third Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Jan/60 | Broken LinkMailing ListThird Party Advisory |
| https://github.com/revive-adserver/revive-adserver/issues/1068 | Issue TrackingThird Party Advisory |
| https://hackerone.com/reports/1081406 | ExploitThird Party Advisory |
| https://www.revive-adserver.com/security/revive-sa-2021-001/ | Vendor Advisory |
| http://packetstormsecurity.com/files/161070/Revive-Adserver-5.0.5-Cross-Site-Scripting-Open-Redirect.html | Third Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2021/Jan/60 | Broken LinkMailing ListThird Party Advisory |
| https://github.com/revive-adserver/revive-adserver/issues/1068 | Issue TrackingThird Party Advisory |
| https://hackerone.com/reports/1081406 | ExploitThird Party Advisory |
| https://www.revive-adserver.com/security/revive-sa-2021-001/ | Vendor Advisory |
Track CVE-2021-22873 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22873), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.