CSRF Vulnerability in Revive Adserver by Revive Adserver Team
CVE-2026-50743
5.4MEDIUM
What is CVE-2026-50743?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the zone-include.php script of Revive Adserver 6.0.7. This flaw allows an attacker to craft malicious GET or POST requests that can manipulate the linking and unlinking of banners or campaigns to zones without proper validation of the CSRF token. This unauthorized access could enable an attacker to perform administrative tasks on behalf of an authenticated user, posing significant security risks to the integrity of the ad management process.
Affected Version(s)
Adserver 0 <= 6.0.7
