A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing user‑supplied input to be reflected without escaping.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/3793243 | Issue Tracking |
Configurations
History
29 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CPE | cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:* | |
| First Time |
Revive-adserver revive Adserver
Revive-adserver |
|
| References | () https://hackerone.com/reports/3793243 - Issue Tracking |
26 Jun 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-26 02:16
Updated : 2026-06-29 20:17
NVD link : CVE-2026-50745
Mitre link : CVE-2026-50745
CVE.ORG link : CVE-2026-50745
JSON object : View
Products Affected
revive-adserver
- revive_adserver
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
