Impact
The vulnerability is a stored XSS that occurs in the maintenance‑acl‑check.php and maintenance‑banners‑check.php tools of Revive AdServer 6.0.7. Entity names entered by users are displayed without escaping, allowing a malicious script to be stored and executed when an administrator opens the affected pages. The effect is client‑side script execution in the administrator’s browser, which can lead to cookie theft, session hijacking, or defacement. The weakness is a classic Cross‑Site Scripting flaw (CWE‑79).
Affected Systems
Revive AdServer version 6.0.7. The specific modules impacted are maintenance‑acl‑check.php and maintenance‑banners‑check.php, which administrators use for routine maintenance tasks.
Risk and Exploitability
The CVSS score is 4.4, indicating low severity. No EPSS score is available and the issue is not listed in the CISA KEV catalogue. The vulnerability requires the attacker to influence stored entity names and relies on an administrator eventually accessing the affected pages, which bounds the attack to a local or administrative vector. Consequently, the likelihood of exploitation is limited to environments where administrators use the vulnerable tools without additional safeguards.
OpenCVE Enrichment