CVE Vulnerabilities

CVE-2025-52666

Use of Externally-Controlled Format String

Published: Nov 20, 2025 | Modified: Dec 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

NameVendorStart VersionEnd Version
Revive_adserverRevive-adserver*5.5.2 (including)
Revive_adserverRevive-adserver6.0.0 (including)6.0.1 (including)

Potential Mitigations

References