Security Advisory

CVE-2025-52667

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-11-20 19:10:15
Last updated 2025-12-01 20:09:24
Assigner hackerone
State PUBLISHED

Description

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.