Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://hackerone.com/reports/3399809 |
|
Tue, 02 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revive-adserver
Revive-adserver revive Adserver |
|
| CPEs | cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Revive-adserver
Revive-adserver revive Adserver |
|
| Metrics |
cvssV3_1
|
Mon, 01 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
ssvc
|
ssvc
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revive
Revive adserver |
|
| Vendors & Products |
Revive
Revive adserver |
Thu, 20 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-12-01T20:09:24.236Z
Reserved: 2025-06-18T15:00:00.895Z
Link: CVE-2025-52667
Updated: 2025-11-20T20:56:22.756Z
Status : Analyzed
Published: 2025-11-20T20:16:22.830
Modified: 2025-12-02T20:24:38.320
Link: CVE-2025-52667
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:09:59Z