Aquaplatform

Revive Adserver

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 20.01.2026 20:48:48
  • Zuletzt bearbeitet 30.01.2026 20:14:51

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a...

  • EPSS 0.04%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 30.01.2026 20:17:33

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error...

  • EPSS 0.03%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 30.01.2026 20:15:53

HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by ot...

  • EPSS 0.04%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 03.02.2026 21:05:31

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator ...

  • EPSS 0.04%
  • Veröffentlicht 20.01.2026 20:48:47
  • Zuletzt bearbeitet 03.02.2026 21:04:36

HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged i...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.12.2025 01:42:06
  • Zuletzt bearbeitet 30.12.2025 14:31:58

HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation h...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 20.11.2025 19:07:42
  • Zuletzt bearbeitet 14.01.2026 21:16:56

HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for the stored XSS

Exploit
  • EPSS 0.01%
  • Veröffentlicht 20.11.2025 19:07:15
  • Zuletzt bearbeitet 14.01.2026 21:18:27

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate ...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 20.11.2025 19:06:52
  • Zuletzt bearbeitet 14.01.2026 21:23:44

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page,...