MEDIUM
CVE-2026-50740
CVSS
5.4
Description
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.
Summary dbcve.org
A reflected XSS vulnerability in Revive Adserver's zone-include.php script allows low-privileged users to inject malicious JavaScript through the refresh parameter of the iFrame invocation tag due to missing input sanitization.
Mitigation
Upgrade to a patched version of Revive Adserver, or implement proper input validation and sanitization on the refresh parameter in zone-include.php to neutralize malicious script execution.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.38%
Probability of exploitation in next 30 days
32.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.