CyberRota Analysis
AI-GeneratedA CSRF vulnerability in the `zone-include.php` script of Revive Adserver 6.0.7 allows attackers to manipulate banner or campaign associations without proper CSRF token verification. This could enable unauthorized changes by executing crafted GET or POST requests on behalf of an authenticated administrator. Organizations using this version of Revive Adserver should prioritize patching to mitigate potential unauthorized access and manipulation of ad configurations.
Original NVD Description
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.