CVE-2026-50740
MEDIUM
NVD
CVSS Score
6.1
Severity
MEDIUM
Published
Jun 26, 2026
Vendor
unknown
Description
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.