The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 12 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revive-adserver
Revive-adserver revive Adserver |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:* cpe:2.3:a:revive-adserver:revive_adserver:6.0.0:rc1:*:*:*:*:*:* |
|
| Vendors & Products |
Revive-adserver
Revive-adserver revive Adserver |
|
| Metrics |
cvssV3_1
|
Mon, 03 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 31 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revive
Revive adserver |
|
| Vendors & Products |
Revive
Revive adserver |
Thu, 30 Oct 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser. The session cookie cannot be accessed, but a number of other operations could be performed. The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter. | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-12-01T19:12:38.766Z
Reserved: 2025-02-20T01:00:01.798Z
Link: CVE-2025-27208
Updated: 2025-11-03T17:32:21.909Z
Status : Modified
Published: 2025-10-31T00:15:36.190
Modified: 2025-12-01T20:15:50.553
Link: CVE-2025-27208
No data.
OpenCVE Enrichment
Updated: 2025-10-31T10:13:14Z