← Back

CVE-2026-50742

nvd nist
Published: Jun 26, 2026Modified: Jun 29, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the affected maintenance tools is not entirely under the attacker's control.

Affected (1)

Revive Adserver
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.0.8

References (1)

Source: support@hackerone.com
Issue TrackingThird Party Advisory

Timeline

No history available yet.