3.5
/ 10
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Description
Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.
Basic Information
ID
CVE-2025-55123
Source
hackerone
Published
Nov 20, 2025 at 19:10
Modified
Nov 20, 2025 at 21:40
Affected Product
Vendor
Revive
Product
Revive Adserver
Version
6
Affected Versions
Revive Revive Adserver 6
Revive Revive Adserver 5
Revive Revive Adserver 5