PT-2008-2914 · Woltlab · Woltlab Burning Board (Wbb) Lite
Nbbn
·
Published
2008-03-13
·
Updated
2018-10-11
·
CVE-2008-1323
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WoltLab Burning Board Lite (wBB) version 2 Beta 1
Description
A cross-site request forgery (CSRF) issue exists, allowing remote attackers to perform actions as other users. This can be exploited to delete threads via the ThreadDelete action.
Recommendations
For version 2 Beta 1, consider implementing CSRF protection mechanisms to prevent unauthorized actions, such as validating request tokens or using same-site cookies to restrict request origins. As a temporary workaround, restrict access to the ThreadDelete action to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woltlab Burning Board (Wbb) Lite