CVE-2025-27208
MEDIUM EPSS 68.6%
Published Oct 31, 20258mo ago · Modified Jun 17, 20262w ago
6.1 CVSS 3.1
Published Oct 31, 2025 8mo ago
Last Modified Jun 17, 2026 2w ago
Description
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser. The session cookie cannot be accessed, but a number of other operations could be performed. The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
68.6% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-79 Cross-site Scripting Injection
Affected Products 2
| Vendor | Product | Version | Range |
|---|---|---|---|
| revive-adserver | revive_adserver | * | <6.0.0 |
| revive-adserver | revive_adserver | 6.0.0 | any |
References 2
- seclists.org http://seclists.org/fulldisclosure/2025/Oct/20
- hackerone.com https://hackerone.com/reports/3091390
Remediation
- seclists.org http://seclists.org/fulldisclosure/2025/Oct/20
- hackerone.com https://hackerone.com/reports/3091390