PT-2019-14914 · Phpbb Limited · Phpbb
Published
2019-09-30
·
Updated
2022-05-24
·
CVE-2019-16993
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpBB versions prior to 3.1.7-PL1
Description
The issue concerns improper verification of a CSRF token on the BBCode page in the Administration Control Panel. This could potentially allow for a CSRF attack if an attacker also obtains the session id of a reauthenticated administrator.
Recommendations
For versions prior to 3.1.7-PL1, update to version 3.1.7-PL1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Administration Control Panel to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpbb