HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the tracker-delete.php script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.
| Software | From | Fixed in |
|---|---|---|
| aquaplatform / revive_adserver | - | 6.0.4.x |