Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.
References
| Link | Resource |
|---|---|
| https://hackerone.com/reports/3398283 | Exploit Issue Tracking Third Party Advisory |
| https://hackerone.com/reports/3398283 | Exploit Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
25 Nov 2025, 18:57
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Revive-adserver revive Adserver
Revive-adserver |
|
| CPE | cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:* | |
| References | () https://hackerone.com/reports/3398283 - Exploit, Issue Tracking, Third Party Advisory |
20 Nov 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://hackerone.com/reports/3398283 - | |
| CWE | CWE-284 |
20 Nov 2025, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-20 20:16
Updated : 2025-11-25 18:57
NVD link : CVE-2025-48986
Mitre link : CVE-2025-48986
CVE.ORG link : CVE-2025-48986
JSON object : View
Products Affected
revive-adserver
- revive_adserver
CWE
CWE-284
Improper Access Control
