CVE-2025-52664 Details
Description
SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users
A SQL injection vulnerability has been identified in Revive Adserver version 6.0.0. The issue arises in the administrative search feature, specifically within the 'admin-search.php' file. The vulnerability allows authenticated users to send specially crafted payloads that could disrupt operations or facilitate unauthorized access to information. This flaw is rooted in improper input validation, as user-controlled data is directly incorporated into SQL queries without adequate sanitization or parameterization.
Users can update to Revive Adserver version 6.0.1, which addresses this vulnerability by properly sanitizing the 'keyword' parameter before it is used in database queries. The patch is available as part of the official release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2025/Oct/21 | CVE | Mailing ListPatchThird Party Advisory |
| https://hackerone.com/reports/3395221 | [email protected] | ExploitIssue TrackingPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| revive-adserver revive adserver | 6.0.0 - |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | CVE Modified | CISA-ADP |
| Nov 12, 2025 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 31, 2025 | New CVE Received | [email protected] |