Revive

Adserver

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 03.02.2026 21:04:36

HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged i...

  • EPSS 0.24%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 30.01.2026 20:15:53

HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by ot...

  • EPSS 0.22%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 30.01.2026 20:17:33

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 02.12.2025 01:42:06
  • Zuletzt bearbeitet 30.12.2025 14:31:58

HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation h...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 02.12.2025 20:19:57

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 25.11.2025 18:57:29

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 20.11.2025 19:11:36
  • Zuletzt bearbeitet 25.11.2025 18:56:45

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 02.12.2025 20:05:41

Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 02.12.2025 20:17:35

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

Exploit
  • EPSS 0.29%
  • Veröffentlicht 20.11.2025 19:10:15
  • Zuletzt bearbeitet 02.12.2025 20:19:15

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.