VYPR
Medium severity5.4NVD Advisory· Published Nov 20, 2025· Updated Jun 17, 2026

CVE-2025-55123

CVE-2025-55123

Description

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

Affected products

3
  • cpe:2.3:a:revive-adserver:revive_adserver:6.0.0:-:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:revive-adserver:revive_adserver:6.0.0:-:*:*:*:*:*:*
    • (no CPE)range: <= 5.5.2, <= 6.0.1
    • (no CPE)range: 6

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.