CVE-2026-50743: CSRF
A CSRF vulnerability exists in the zone-include.php script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50743?
The severity of CVE-2026-50743 is medium, with a CVSS score of 5.4.
How do I fix CVE-2026-50743?
To fix CVE-2026-50743, ensure that CSRF tokens are validated on all state-changing requests within the Revive Adserver application.
What does CVE-2026-50743 affect?
CVE-2026-50743 affects the `zone-include.php` script in Revive Adserver version 6.0.7.
What is the nature of the vulnerability in CVE-2026-50743?
CVE-2026-50743 is a CSRF vulnerability that allows an attacker to manipulate banners or campaigns on behalf of an authenticated user.
When was CVE-2026-50743 published?
CVE-2026-50743 was published on July 20, 2026.