Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.
| Software | From | Fixed in |
|---|---|---|
| revive-adserver / revive_adserver | - | 5.5.2.x |
| revive-adserver / revive_adserver | 6.0.0 | 6.0.1.x |