Back

CVE-2019-5434

CRITICAL

An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0.

Published: May 6, 2019 Modified: Jun 17, 2026
CWE-502 CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
revive-sas revive_adserver * < 4.2.0

GitHub Security Advisory GHSA-7chh-x9j3-4vhx

An attacker could send a specifically crafted payload to the XML-RPC invocation script and...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 57.02%

Top 1% most likely to be exploited

Threat Score 56.3 / 100

Data Sources

NVD EPSS GitHub