Unrated severityNVD Advisory· Published Jan 20, 2026· Updated Jan 21, 2026
CVE-2026-21642
CVE-2026-21642
Description
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php and channel-acl.php scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the browser and malicious scripts would be executed.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.