Medium severity5.4NVD Advisory· Published Jun 26, 2026· Updated Jun 29, 2026
CVE-2026-50742
CVE-2026-50742
Description
A stored XSS vulnerabilities exists in the maintenance-acl-check.php and maintenance-banners-check.php tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the affected maintenance tools is not entirely under the attacker's control.
Affected products
2cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*range: <6.0.8
- (no CPE)range: <=6.0.7
Patches
Vulnerability mechanics
References
1- hackerone.com/reports/3781311nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.