Input Sanitization Flaw in Stats-Video Script Affects Vendor Product
CVE-2026-50745

4.7MEDIUM

Key Information:

Vendor

Revive

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-50745?

A vulnerability exists in the stats-video.php script due to a lack of proper sanitization of user inputs. The URLs constructed for this script did not adhere to security best practices, which allowed the output from the Smarty custom helper function to be displayed without necessary encoding or sanitization. Consequently, this flaw enables the potential for user-supplied input to be reflected unsafely, posing a risk of code injection or similar threats.

Affected Version(s)

Adserver 0 <= 6.0.7

References

CVSS V3.0

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mahmoud Khaled (Kanon4)
.