CVE Explorer
CVE-2026-50743
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Adserver","vendor":"Revive","versions":[{"lessThanOrEqual":"6.0.7","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a6b306dd27f0da0701cfeda1cd6aca5e49772c3b42992bde7fcadb3bdcb4b845 · sha256:dc5d9d13f19dc97d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","version":"3.0"},"metric_type":"cvssV3_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a6b306dd27f0da0701cfeda1cd6aca5e49772c3b42992bde7fcadb3bdcb4b845 · sha256:dc5d9d13f19dc97d… · /containers/cna/metrics/0/cvssV3_0
CWE assertions
1 source assertion{"cweId":"CWE-352","description":"CWE-352 Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a6b306dd27f0da0701cfeda1cd6aca5e49772c3b42992bde7fcadb3bdcb4b845 · sha256:dc5d9d13f19dc97d… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://hackerone.com/reports/3781691"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a6b306dd27f0da0701cfeda1cd6aca5e49772c3b42992bde7fcadb3bdcb4b845 · sha256:dc5d9d13f19dc97d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.