A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the affected maintenance tools is not entirely under the attacker's control.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/3781311 | Issue Tracking Third Party Advisory |
Configurations
History
29 Jun 2026, 20:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://hackerone.com/reports/3781311 - Issue Tracking, Third Party Advisory | |
| CPE | cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:* | |
| First Time |
Revive-adserver revive Adserver
Revive-adserver |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
26 Jun 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-26 02:16
Updated : 2026-06-29 20:20
NVD link : CVE-2026-50742
Mitre link : CVE-2026-50742
CVE.ORG link : CVE-2026-50742
JSON object : View
Products Affected
revive-adserver
- revive_adserver
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
