CVE-2016-9455: CSRF
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable to CSRF attacks: www/admin/banner-acl.php, www/admin/banner-activate.php, www/admin/banner-advanced.php, www/admin/banner-modify.php, www/admin/banner-swf.php, www/admin/banner-zone.php, www/admin/tracker-modify.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9455?
CVE-2016-9455 is classified as a medium severity vulnerability due to its potential for exploitation via CSRF attacks.
How do I fix CVE-2016-9455?
To fix CVE-2016-9455, upgrade to Revive Adserver version 3.2.3 or later.
What types of attacks can be carried out exploiting CVE-2016-9455?
Exploiting CVE-2016-9455 can allow attackers to perform unauthorized actions on behalf of authenticated users.
Which versions of Revive Adserver are affected by CVE-2016-9455?
CVE-2016-9455 affects all versions of Revive Adserver prior to 3.2.3.
Is user authentication at risk due to CVE-2016-9455?
Yes, user authentication can be compromised as CVE-2016-9455 allows CSRF attacks that exploit authenticated users' sessions.