CVE-2016-9456: CSRF
Published Mar 28, 2017
·Updated
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other potential CSRF vulnerabilities. Over 20+ such issues were fixed.
Affected Software
1 affected component
revive-adserver Revive Adserver<=3.2.2
Remediation
Patch Available
Event History
Mar 28, 2017
CVE Published
via MITRE·02:46 AM
Data Sourced
via MITRE·02:46 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9456?
CVE-2016-9456 has a medium severity level due to its potential for Cross-Site Request Forgery (CSRF) attacks.
2
How do I fix CVE-2016-9456?
To fix CVE-2016-9456, upgrade Revive Adserver to version 3.2.3 or later.
3
What type of vulnerability is CVE-2016-9456?
CVE-2016-9456 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of Revive Adserver are affected by CVE-2016-9456?
CVE-2016-9456 affects all versions of Revive Adserver prior to 3.2.3.
5
What are the potential impacts of CVE-2016-9456?
The potential impacts of CVE-2016-9456 include unauthorized actions being performed on behalf of logged-in users.