« Volver al listado

CVE-2025-52669

Estado: AnalizadaMedia (4.3)—

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-52669",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-52669",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-11-20T21:43:22.750442Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "support@hackerone.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "Revive",
          "product": "Revive Adserver",
          "versions": [
            {
              "status": "affected",
              "version": "6",
              "versionType": "semver",
              "lessThanOrEqual": "6.0.1"
            },
            {
              "status": "affected",
              "version": "5",
              "versionType": "semver",
              "lessThanOrEqual": "5.5.2"
            },
            {
              "status": "unaffected",
              "version": "6.0.2",
              "versionType": "semver",
              "lessThanOrEqual": "6.0.2"
            },
            {
              "status": "unaffected",
              "version": "5.5.3",
              "versionType": "semver",
              "lessThanOrEqual": "5.5.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-11-20T20:16:23.140",
  "references": [
    {
      "url": "https://hackerone.com/reports/3401464",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://hackerone.com/reports/3401464",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system."
    },
    {
      "lang": "es",
      "value": "Políticas de diseño inseguro en el sistema de gestión de usuarios de Revive Adserver 5.5.2 y 6.0.1 y versiones anteriores causan que usuarios no administradores tengan acceso al nombre de contacto y la dirección de correo electrónico de otros usuarios en el sistema."
    }
  ],
  "lastModified": "2026-09-26T00:10:00.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47AC2D81-BA0C-404A-B6F6-31151956D422",
              "versionEndIncluding": "5.5.2"
            },
            {
              "criteria": "cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42E4B7BD-5F7B-4FBE-93D2-C19F30FA5A51",
              "versionEndIncluding": "6.0.1",
              "versionStartIncluding": "6.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}