PT-2026-51558 · Unknown · Revive Adserver
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Revive Adserver versions prior to 6.0.7
Description
An access control bypass allows a user with advertiser-level privileges to activate or deactivate a banner, regardless of whether they have been granted the necessary permissions. This occurs because the 'banner-edit.php' script allows the banner status to be overwritten based solely on banner edit permissions. The issue is rooted in the presence of the status field within the hidden form fields of the banner edit screen.
Recommendations
Update to a version later than 6.0.6.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Revive Adserver