Medium severity5.4NVD Advisory· Published Nov 20, 2025· Updated Jun 17, 2026
CVE-2025-55123
CVE-2025-55123
Description
Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.
Affected products
3cpe:2.3:a:revive-adserver:revive_adserver:6.0.0:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:revive-adserver:revive_adserver:6.0.0:-:*:*:*:*:*:*
- (no CPE)range: <= 5.5.2, <= 6.0.1
- (no CPE)range: 6
Patches
Vulnerability mechanics
References
1- hackerone.com/reports/3404968nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.