CVE-2025-52670
7.1Revive · Revive Adserver
A missing authorization check in Revive Adserver allows authenticated users to delete banners belonging to other accounts.
Executive summary
A vulnerability in Revive Adserver allows authenticated users to unauthorizedly delete banners, posing a significant risk to data integrity.
Vulnerability
This is an improper authorization vulnerability where the application fails to validate if an authenticated user possesses the necessary permissions to modify or delete resources owned by other accounts. The vulnerability is triggered via network access by an authenticated user.
Business impact
The ability for a user to delete banners owned by other accounts directly impacts the integrity of advertising campaigns and operational workflows. With a CVSS score of 7.1, this vulnerability is classified as High severity, as it facilitates unauthorized modification of data within the platform, potentially leading to significant operational disruption or loss of marketing assets.
Remediation
Immediate Action: Upgrade Revive Adserver to version 5.5.3 or 6.0.2 to incorporate the necessary authorization checks.
Proactive Monitoring: Review web server and application access logs for unusual patterns of account activity or unauthorized attempts to access or delete banner resources.
Compensating Controls: Implement strict access control lists and review user roles within the Adserver to ensure that only authorized personnel have access to sensitive management functions.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available in the provided data.
Analyst recommendation
Given the High severity of this authorization flaw and the existence of a proof-of-concept, administrators should prioritize updating to the patched versions immediately. Failure to address this vulnerability allows malicious or compromised accounts to disrupt advertising operations by deleting assets belonging to other users.