CVE-2008-7192: CSRF
Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID parameter in a delete action in a PM page, a different vulnerability than CVE-2008-0472.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7192?
CVE-2008-7192 is classified as a medium severity vulnerability due to its potential impact on user authentication.
How do I fix CVE-2008-7192?
To fix CVE-2008-7192, you should upgrade to a patched version of WoltLab Burning Board that addresses this CSRF vulnerability.
Who is affected by CVE-2008-7192?
Users of WoltLab Burning Board version 3.0.1 and possibly other 3.x versions are affected by CVE-2008-7192.
What type of vulnerability is CVE-2008-7192?
CVE-2008-7192 is a cross-site request forgery (CSRF) vulnerability allowing unauthorized actions on behalf of a user.
What can an attacker do with CVE-2008-7192?
An attacker exploiting CVE-2008-7192 can hijack user authentication to delete private messages.