CVE-2025-48986

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.
References
Link Resource
https://hackerone.com/reports/3398283 Exploit Issue Tracking Third Party Advisory
https://hackerone.com/reports/3398283 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*
cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*

History

25 Nov 2025, 18:57

Type Values Removed Values Added
First Time Revive-adserver revive Adserver
Revive-adserver
CPE cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*
References () https://hackerone.com/reports/3398283 - () https://hackerone.com/reports/3398283 - Exploit, Issue Tracking, Third Party Advisory

20 Nov 2025, 22:15

Type Values Removed Values Added
References () https://hackerone.com/reports/3398283 - () https://hackerone.com/reports/3398283 -
CWE CWE-284

20 Nov 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-20 20:16

Updated : 2025-11-25 18:57


NVD link : CVE-2025-48986

Mitre link : CVE-2025-48986

CVE.ORG link : CVE-2025-48986


JSON object : View

Products Affected

revive-adserver

  • revive_adserver
CWE
CWE-284

Improper Access Control