Home

Description

SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users

PUBLISHED Reserved 2025-06-18 | Published 2025-10-30 | Updated 2025-11-03 | Assigner hackerone




HIGH: 8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/CR:X/IR:X/AR:X

Product status

6.0.0 (semver)
affected

6.0.1 (semver)
unaffected

References

seclists.org/fulldisclosure/2025/Oct/21

hackerone.com/reports/3395221

cve.org (CVE-2025-52664)

nvd.nist.gov (CVE-2025-52664)

Download JSON