PHP Object Injection Vulnerability in Revive Adserver by Revive Adserver
CVE-2019-5434

9.8CRITICAL

Key Information:

Vendor

Revive-sas

Vendor
CVE Published:
6 May 2019

What is CVE-2019-5434?

The vulnerability in Revive Adserver allows attackers to craft malicious payloads to exploit the XML-RPC invocation script via the 'what' parameter. This leads to the dangerous unserialize() function call, which may result in PHP object injection. Potential exploits could enable attackers to deliver malware through compromised instances of Revive Adserver, affecting third-party websites. This security flaw was remedied in version 4.2.0, highlighting the importance of keeping software updated.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Revive Adserver Fixed version v4.2.0

References

EPSS Score

91% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.