Beveiligingsadvies

CVE-2026-50740

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-26 01:11:14
Laatst bijgewerkt 2026-07-08 19:42:43
Toegewezen door hackerone
CVSS-score 6.1
Status PUBLISHED

Beschrijving

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.