SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-50743

MEDIUM · CVSS 5.4 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

A CSRF vulnerability in the `zone-include.php` script of Revive Adserver 6.0.7 allows attackers to manipulate banner or campaign associations without proper CSRF token verification. This could enable unauthorized changes by executing crafted GET or POST requests on behalf of an authenticated administrator. Organizations using this version of Revive Adserver should prioritize patching to mitigate potential unauthorized access and manipulation of ad configurations.

CVE
CVE-2026-50743
Severity
MEDIUM
CVSS
5.4
EPSS
0.24%

Original NVD Description

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.