CVE-2025-52667
20.11.2025, 20:16
Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.
| Vendor | Product | Version |
|---|---|---|
| revive-adserver | revive_adserver | 𝑥 ≤ 5.5.2 |
| revive-adserver | revive_adserver | 6.0.0 ≤ 𝑥 ≤ 6.0.1 |
𝑥
= Vulnerable software versions
References