PT-2026-51559 · Unknown · Revive Adserver
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Revive Adserver versions prior to 6.0.7
Description
Insufficient validation of user input occurs when saving delivery limitations. A low-privileged user can introduce an unexpected component parameter to inject malicious PHP code into the
compiledlimitations field, which is subsequently executed during banner delivery.Recommendations
Update to version 6.0.7 or later to ensure input sanitization filters out unexpected parameters.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Revive Adserver