CVE-2025-55124: XSS
Published Nov 20, 2025
·Updated
Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.
Affected Software
2 affected components
Revive Adserver>=6.0.0
revive-adserver Revive Adserver>=6.0.0<=6.0.1
Event History
Nov 20, 2025
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionSeverity
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55124?
CVE-2025-55124 is classified as a medium severity vulnerability due to its potential to allow reflected XSS attacks.
2
How do I fix CVE-2025-55124?
To fix CVE-2025-55124, upgrade Revive Adserver to the latest version where this vulnerability has been patched.
3
Which versions of Revive Adserver are affected by CVE-2025-55124?
CVE-2025-55124 affects all versions of Revive Adserver starting from 6.0.0.
4
What type of attack is associated with CVE-2025-55124?
CVE-2025-55124 is associated with a reflected cross-site scripting (XSS) attack affecting the banner-zone.php script.
5
Where can I find more information about CVE-2025-55124?
More information about CVE-2025-55124 can be found in the official CVE database and security advisories from Revive Adserver.