Revive Adserver Stored Cross-Site Scripting Vulnerability in Advertiser Campaign Names

Vulnerability

A stored cross-site scripting vulnerability has been identified in Revive Adserver, specifically in version 6.0.2. This issue allows low-privilege authenticated users to inject HTML and JavaScript into campaign names. The injected scripts are executed when an administrator accesses the Banners advertiser/campaign picker, potentially leading to session hijacking, unauthorized administrative actions, or exposure of sensitive data.

Impact

Exploitation of this vulnerability allows for the execution of injected scripts in the context of an administrator's browser. This could result in stealing admin session cookies, performing silent actions through the admin account, disclosing sensitive information visible to admins, or further compromising the server's infrastructure.

Reproduction

To reproduce this vulnerability, log in as a low-privilege user and create or edit a campaign name by injecting a script payload. Once the campaign is saved, an administrator accessing the Banners modal will trigger the execution of the injected script.

Remediation

Users are advised to update to Revive Adserver version 6.0.2, which addresses this vulnerability.

Added: Nov 20, 2025, 7:20 PM
Updated: Nov 20, 2025, 7:20 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
6.5
remediation
7.7
relevance
1.1
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.