Stored XSS Vulnerability in Revive Adserver by Revive Adserver
CVE-2025-52668
8.7HIGH
What is CVE-2025-52668?
In Revive Adserver, an improper input neutralization issue exists in the stats-conversions.php script. This vulnerability allows attackers to carry out stored cross-site scripting (XSS) attacks, potentially leading to information disclosure or session hijacking. Attackers can exploit this flaw to inject malicious scripts that execute under the user's context, compromising security and privacy.
Affected Version(s)
Revive Adserver 6 <= 6.0.1
Revive Adserver 5 <= 5.5.2
Revive Adserver 6.0.2
