Impact
A cross‑site request forgery flaw exists in the zone-include.php script of Revive Adserver 6.0.7. The script allows linking and unlinking banners or campaigns to zones through crafted GET or POST requests without validating a CSRF token, enabling an attacker to perform these actions on behalf of an authenticated administrator.
Affected Systems
Revive Adserver version 6.0.7 is affected. No other versions or components are listed as vulnerable; the issue is confined to the zone-include.php file handling banner and campaign association actions.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity issue. The EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV. Exploitation requires an authenticated administrator session and a method for delivering a malicious request to the admin, such as a social engineering attack or a malicious link sent from a trusted environment. Because the attack vector is not a true zero‑click exploit, the risk remains meaningful but not critical.
OpenCVE Enrichment