CVE-2013-5954

medium
Published 2014-04-25 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertisers via admin/advertiser-delete.php, (3) banners via admin/banner-delete.php, (4) campaigns via admin/campaign-delete.php, (5) channels via admin/channel-delete.php, (6) affiliate websites via admin/affiliate-delete.php, or (7) zones via admin/zone-delete.php.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
revive-adserverrevive_adserver{"endIncluding":"3.0.4"}
openxopenx{"endIncluding":"2.8.11"}
openxopenx2.8
openxopenx2.8.1
openxopenx2.8.2
openxopenx2.8.3
openxopenx2.8.4
openxopenx2.8.5
openxopenx2.8.6
openxopenx2.8.7
openxopenx2.8.8
openxopenx2.8.9
openxopenx2.8.10

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.