---
id: CVE-2025-55128
title: >-
  HackerOne community member Dang Hung Vi (vidang04) has reported an
  uncontrolled resource consumption vulnerability in the “userlog-index.php”
summary: >-
  HackerOne community member Dang Hung Vi (vidang04) has reported an
  uncontrolled resource consumption vulnerability in the “userlog-index.php”. An
  attacker with access to the admin interface could request an arbitrarily large
  number of it…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: aquaplatform
product: revive_adserver
affected:
  - 'revive_adserver >= 6.0.0, < 6.0.3'
patched:
  - revive_adserver 6.0.3
published: '2025-11-20'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55128'
references:
  - url: 'https://hackerone.com/reports/3413890'
    label: support@hackerone.com
tags:
  - nvd
epss: 0.00399
epssPercentile: 0.31369
ingestedAt: '2026-09-26T00:22:39.977Z'
---

## Overview

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a denial of service.

## Affected

- `revive_adserver >= 6.0.0, < 6.0.3`

## Remediation

Upgrade past the affected range:

- `revive_adserver 6.0.3`
