CVE-2013-5954

medium
Published 2014-04-25 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.8

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertisers via admin/advertiser-delete.php, (3) banners via admin/banner-delete.php, (4) campaigns via admin/campaign-delete.php, (5) channels via admin/channel-delete.php, (6) affiliate websites via admin/affiliate-delete.php, or (7) zones via admin/zone-delete.php.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-39117 webapps php verified
Mahmoud Ghorbanzadeh ยท 2014-03-15

OpenX 2.8.x - Multiple Cross-Site Request Forgery Vulnerabilities

Source code queued for fetch โ€” refresh in a moment.

Application impact

VendorProductVersionsFixed
revive-adserverrevive_adserver{"endIncluding":"3.0.4"}
openxopenx{"endIncluding":"2.8.11"}
openxopenx2.8
openxopenx2.8.1
openxopenx2.8.2
openxopenx2.8.3
openxopenx2.8.4
openxopenx2.8.5
openxopenx2.8.6
openxopenx2.8.7
openxopenx2.8.8
openxopenx2.8.9
openxopenx2.8.10

References

CWEs

CWE-352

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.