Revive Adserver
cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*
- <= 5.5.2
- <= 6.0.1
A reflected cross-site scripting vulnerability has been identified in Revive Adserver versions through 6.0.1, including 5.5.2. The issue arises in the account-preferences-plugin.php file, where the 'group' query parameter is not properly sanitized. This lack of input validation allows the injection of JavaScript, which is executed in the context of the user's browser.
Exploitation of this vulnerability allows for the injection of scripts that execute in the context of the victim's browser, potentially leading to typical cross-site scripting abuses such as UI redress, persistence of phishing content, or session manipulation.
To reproduce this vulnerability, navigate to the account-preferences-plugin.php file in the admin directory of Revive Adserver versions through 6.0.1. Append the 'group' query parameter with a script payload, such as a script tag including a JavaScript alert. The injected script will execute, confirming the presence of the reflected cross-site scripting vulnerability.
Users are advised to update to the latest version of Revive Adserver, as the vulnerability has been fixed in the upcoming security release scheduled for November 5, 2025.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.