PT-2019-13299 · Phpbb Limited · Phpbb
Published
2019-09-27
·
Updated
2022-05-24
·
CVE-2019-13376
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
phpBB version 3.2.7
Description
The issue allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature, leading to stored XSS due to CSRF Token Hijacking.
Recommendations
For phpBB version 3.2.7, update to a version that fixes the CSRF Token Hijacking issue in the Remote Avatar feature to prevent session id theft and stored XSS.
Exploit
Fix
CSRF
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpbb