CVE-2025-55127: Medium severity Aquaplatform Revive Adserver vulnerability
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially leading to confusion.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55127?
CVE-2025-55127 is classified as a moderate severity vulnerability due to improper neutralization of whitespace in usernames.
How do I fix CVE-2025-55127?
To address CVE-2025-55127, ensure that username validation removes leading and trailing whitespace before processing.
Which versions of Revive Adserver are affected by CVE-2025-55127?
CVE-2025-55127 affects Revive Adserver versions from 6.0.0 to 6.0.3.
Who reported CVE-2025-55127?
CVE-2025-55127 was reported by HackerOne community member Dao Hoang Anh (yoyomiski).
What kind of attack can exploit CVE-2025-55127?
CVE-2025-55127 can potentially be exploited to create misleading usernames that could confuse users or impersonate legitimate accounts.