Security Advisory

CVE-2026-50740

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-26 01:11:14
Last updated 2026-07-08 19:42:43
Assigner hackerone
CVSS score 6.1
State PUBLISHED

Description

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.