Insecure User Management in Revive Adserver by Revive Adserver
CVE-2025-52669

4.3MEDIUM

Key Information:

Vendor

Revive

Vendor
CVE Published:
20 November 2025

What is CVE-2025-52669?

An insecure user management design in Revive Adserver versions 5.5.2, 6.0.1, and earlier allows non-administrator users to access sensitive information, including contact names and email addresses of other users within the system. This vulnerability poses a threat to user privacy and highlights the importance of implementing robust access controls. Organizations using affected versions are encouraged to review their user management policies and apply necessary mitigations promptly.

Affected Version(s)

Revive Adserver 6 <= 6.0.1

Revive Adserver 5 <= 5.5.2

Revive Adserver 6.0.2

References

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52669 : Insecure User Management in Revive Adserver by Revive Adserver