Loading
Generated remediation guidance and an executive summary. No account required.
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.
Use CWE-284, Revive-Adserver vendor hub and Revive Adserver product page to widen CVE-2025-48986 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-52664, CVE-2025-52670 and CVE-2025-55124 for nearby disclosures in the same product family.