CVE-2025-52669: Infoleak
Published Nov 20, 2025
·Updated
Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.
Affected Software
3 affected components
Revive Adserver<6.0.1
revive-adserver Revive Adserver<=5.5.2
revive-adserver Revive Adserver>=6.0.0<=6.0.1
Event History
Nov 20, 2025
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionSeverity
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52669?
CVE-2025-52669 has a severity rating of medium due to the exposure of user contact information.
2
How do I fix CVE-2025-52669?
To fix CVE-2025-52669, upgrade to Revive Adserver version 6.0.2 or later where the vulnerability is patched.
3
Which users are affected by CVE-2025-52669?
Non-admin users in Revive Adserver are affected by CVE-2025-52669, as they can access other users' contact details.
4
What versions of Revive Adserver are impacted by CVE-2025-52669?
CVE-2025-52669 affects Revive Adserver versions 5.5.2, 6.0.1, and earlier.
5
What type of vulnerability is CVE-2025-52669?
CVE-2025-52669 is classified as an insecure design vulnerability in the user management system.