MEDIUM

CVE-2026-50740

Revive-adserver Revive Adserver 2026-06-26 CVSS v3.1
CVSS
5.4

Description

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.

Summary dbcve.org

A reflected XSS vulnerability in Revive Adserver's zone-include.php script allows low-privileged users to inject malicious JavaScript through the refresh parameter of the iFrame invocation tag due to missing input sanitization.

Mitigation

Upgrade to a patched version of Revive Adserver, or implement proper input validation and sanitization on the refresh parameter in zone-include.php to neutralize malicious script execution.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.38%
Probability of exploitation in next 30 days
32.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE