PT-2008-2914 · Woltlab · Woltlab Burning Board (Wbb) Lite

Nbbn

·

Published

2008-03-13

·

Updated

2018-10-11

·

CVE-2008-1323

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WoltLab Burning Board Lite (wBB) version 2 Beta 1
Description A cross-site request forgery (CSRF) issue exists, allowing remote attackers to perform actions as other users. This can be exploited to delete threads via the ThreadDelete action.
Recommendations For version 2 Beta 1, consider implementing CSRF protection mechanisms to prevent unauthorized actions, such as validating request tokens or using same-site cookies to restrict request origins. As a temporary workaround, restrict access to the ThreadDelete action to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1323

Affected Products

Woltlab Burning Board (Wbb) Lite