Junglewise Threat Intelligence

CVE-2026-50740: Revive Adserver reflected XSS in zone-include.php

CVE-2026-50740 · Severity: medium · CVSS 6.1 · Published 2026-06-26

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

Revive Adserver, a popular open-source platform for managing digital advertisements, contains a security flaw in its ad delivery scripts. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login sessions or the unauthorized modification of web content seen by the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Revive Adserver versions 6.0.7 and earlier. The flaw is located within the 'zone-include.php' script, which fails to properly sanitize user-supplied input provided via the 'refresh' parameter of the iFrame invocation tag. An unauthenticated remote attacker can exploit this by inducing a user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions on behalf of the user.

Affected products

  • Revive Adserver <= 6.0.7

Timeline

  • 2026-06-26: disclosed: NVD publication date

References

Related threats