A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing user‑supplied input to be reflected without escaping.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/3793243 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-06-26 02:16
Updated : 2026-06-29 20:17
NVD link : CVE-2026-50745
Mitre link : CVE-2026-50745
CVE.ORG link : CVE-2026-50745
JSON object : View
Products Affected
revive-adserver
- revive_adserver
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
