A vulnerability classified as problematic was found in Revive Adserver up to 6.0.4. This impacts an unknown function of the file banner-acl.php. Such manipulation of the argument cap/session_capping/time leads to cross site scripting.

This vulnerability is documented as CVE-2026-21663. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.