Revive Adserver Reflected Cross-Site Scripting Vulnerability in Banner Zone Management

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Revive Adserver versions 6.0.0 and above. The issue arises in the 'banner-zone.php' script, where user input from the 'website' field in the banner search is not properly sanitized before being displayed. This flaw allows an attacker to inject malicious scripts that are executed in the context of the user's browser.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the browser of an affected user, specifically an administrator. This could lead to unauthorized actions being performed in the admin's account, session hijacking (if cookies are not set to HttpOnly), and potentially compromise the entire site.

Reproduction

To reproduce this vulnerability, log into the admin panel of Revive Adserver version 6.0.0 or later. Navigate to the 'Banners' section and select 'Linked Zones'. In the 'Website' search field, insert a script payload, such as a JavaScript alert wrapped in script tags. The injected script will be executed in the browser, demonstrating the cross-site scripting vulnerability.

Remediation

Users are advised to update to the latest version of Revive Adserver, where this vulnerability has been addressed. The patch is available as part of the upcoming security release.

Added: Nov 20, 2025, 8:17 PM
Updated: Nov 20, 2025, 10:25 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
7.9
remediation
0.0
relevance
1.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.