PT-2026-51554 · Unknown · Revive Adserver
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Revive Adserver versions prior to 6.0.7
Description
Insufficient validation of user input during the process of saving delivery limitations allows a low-privileged user to inject malicious PHP code into the
compiledlimitations database field via the logical parameter. This code can then be executed during banner delivery.Recommendations
Update to a version later than 6.0.6 to ensure input sanitization is properly implemented for the logical parameter.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Revive Adserver