ZeroHour

CVE-2025-48986

PoC
CVSS 3.0
8.8 high
EPSS
<1%p48
Published
()
Modified
Description

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Vendors
revive-adserver
Products
revive adserver
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.