CVE-2025-55128: Medium severity Aquaplatform Revive Adserver vulnerability
HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55128?
CVE-2025-55128 has a severity level that is associated with the potential for denial of service due to uncontrolled resource consumption.
How do I fix CVE-2025-55128?
To fix CVE-2025-55128, ensure that user input on the ‘userlog-index.php’ page is properly validated and limit the number of items that an admin can request per page.
Who is affected by CVE-2025-55128?
CVE-2025-55128 affects users of Aquaplatform Revive Adserver versions between 6.0.0 and 6.0.3.
What kind of attack does CVE-2025-55128 allow?
CVE-2025-55128 allows attackers with admin access to perform a denial of service attack by requesting excessive resources through the admin interface.
Is there a patch available for CVE-2025-55128?
As of now, specific patch details are not provided, so it is recommended to check for updates from Aquaplatform for CVE-2025-55128.