CSRF Vulnerability in Revive Adserver by Revive Adserver Team
CVE-2026-50743

5.4MEDIUM

Key Information:

Vendor

Revive

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-50743?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the zone-include.php script of Revive Adserver 6.0.7. This flaw allows an attacker to craft malicious GET or POST requests that can manipulate the linking and unlinking of banners or campaigns to zones without proper validation of the CSRF token. This unauthorized access could enable an attacker to perform administrative tasks on behalf of an authenticated user, posing significant security risks to the integrity of the ad management process.

Affected Version(s)

Adserver 0 <= 6.0.7

References

CVSS V3.0

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Althaf Shajahan (an_gr_y)
.