CVE-2025-55123

Publication date

2025-11-20 19:10:15

Family

hackerone

State

PUBLISHED

Description

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.