CVE-2013-5954

medium

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertisers via admin/advertiser-delete.php, (3) banners via admin/banner-delete.php, (4) campaigns via admin/campaign-delete.php, (5) channels via admin/channel-delete.php, (6) affiliate websites via admin/affiliate-delete.php, or (7) zones via admin/zone-delete.php.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/91889

http://www.securityfocus.com/archive/1/532108/100/0/threaded

http://www.revive-adserver.com/security/revive-sa-2014-001/

http://seclists.org/fulldisclosure/2014/May/68

Details

Source: Mitre, NVD

Published: 2014-04-25

Updated: 2018-10-09

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H

Severity: Medium