Vulnerability Description
Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Revive-Adserver | Revive Adserver | <= 5.5.2 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/3399218ExploitIssue TrackingThird Party Advisory
- https://hackerone.com/reports/3399218ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2025-52666?
CVE-2025-52666 is a vulnerability with a CVSS score of 2.7 (LOW). Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP e...
How severe is CVE-2025-52666?
CVE-2025-52666 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52666?
Check the references section above for vendor advisories and patch information. Affected products include: Revive-Adserver Revive Adserver.