CVE-2025-52668
20.11.2025, 20:16
Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.
| Vendor | Product | Version |
|---|---|---|
| revive-adserver | revive_adserver | 𝑥 ≤ 5.5.2 |
| revive-adserver | revive_adserver | 6.0.0 ≤ 𝑥 ≤ 6.0.1 |
𝑥
= Vulnerable software versions