cvedb.io
CVE-2026-50743
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2026-07-20T17:17:57.500 · Last modified 2026-07-20T19:17:24.380

Summary

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.