Vulnerabilities
Vulnerable Software
Aquaplatform:  Security Vulnerabilities
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation has been independently reported by other HackerOne users, such as itz_hari_ and khoof.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-12-02
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially leading to confusion.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-11-20
HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a denial of service.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-11-20
HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for the stored XSS
CVSS Score
6.5
EPSS Score
0.0
Published
2025-11-20


Contact Us

Shodan ® - All rights reserved