Revive

Adserver

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 25.06.2026 19:52:36

The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.

  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 23.06.2026 18:17:43

A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by o...

  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 23.06.2026 18:17:43

A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same ...

  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 23.06.2026 18:17:43

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensur...

  • EPSS 0.21%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 23.06.2026 18:17:43

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved ...

  • EPSS 0.3%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 25.06.2026 19:52:36

Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabi...

  • EPSS 0.3%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 25.06.2026 19:52:36

Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through us...

  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 23.06.2026 18:17:51

A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, leading to inconsistent ownership relationships. This...

  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 23.06.2026 18:17:51

An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten sole...

  • EPSS 0.4%
  • Veröffentlicht 23.06.2026 16:14:38
  • Zuletzt bearbeitet 23.06.2026 18:17:52

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which...