PT-2019-13299 · Phpbb Limited · Phpbb

Published

2019-09-27

·

Updated

2022-05-24

·

CVE-2019-13376

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions phpBB version 3.2.7
Description The issue allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature, leading to stored XSS due to CSRF Token Hijacking.
Recommendations For phpBB version 3.2.7, update to a version that fixes the CSRF Token Hijacking issue in the Remote Avatar feature to prevent session id theft and stored XSS.

Exploit

Fix

CSRF

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13376
DLA-1942-1
DLA-1942-2
GHSA-6MH2-98GR-WV76

Affected Products

Phpbb