Revive

Adserver

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 20.01.2026 20:48:48
  • Zuletzt bearbeitet 30.01.2026 20:14:51

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a...

  • EPSS 0.03%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 03.02.2026 21:04:36

HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged i...

  • EPSS 0.03%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 03.02.2026 21:05:31

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator ...

  • EPSS 0.02%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 30.01.2026 20:15:53

HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by ot...

  • EPSS 0.03%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 30.01.2026 20:17:33

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.12.2025 01:42:06
  • Zuletzt bearbeitet 30.12.2025 14:31:58

HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation h...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 25.11.2025 18:57:29

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 25.11.2025 18:56:45

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 02.12.2025 20:19:57

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

Exploit
  • EPSS 0.01%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 02.12.2025 20:19:15

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.