CVE-2025-52671: Medium severity Revive Adserver vulnerability
Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52671?
CVE-2025-52671 has been classified as a moderate severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2025-52671?
To fix CVE-2025-52671, upgrade Revive Adserver to version 6.0.2 or higher.
What are the implications of CVE-2025-52671 for non-admin users?
Non-admin users can potentially access sensitive information about the software and database versions through SQL error messages due to CVE-2025-52671.
Which versions of Revive Adserver are affected by CVE-2025-52671?
CVE-2025-52671 affects Revive Adserver versions 5.5.2 and 6.0.1 and earlier.
Is there a workaround for CVE-2025-52671 pending updates?
Until updates are applied, restricting access to error messages in the application settings can help mitigate the risks of CVE-2025-52671.