CVE-2019-11767: SSRF
Published May 5, 2019
·Updated
Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.
Affected Software
2 affected componentsFixes available
composer/phpbb/phpbb<3.2.6
3.2.6
phpBB phpbb<3.2.6
Event History
May 5, 2019
CVE Published
via MITRE·05:29 AM
Data Sourced
via MITRE·05:29 AM
Description
May 24, 2022
Advisory Published
via GitHub·04:45 PM
Frequently Asked Questions
1
What is CVE-2019-11767?
CVE-2019-11767 is a Server Side Request Forgery (SSRF) vulnerability in phpBB before version 3.2.6.
2
How does CVE-2019-11767 work?
CVE-2019-11767 allows an attacker to check for the existence of files and services on the local network of the host through the remote avatar upload function.
3
Is phpBB version 3.2.6 affected by CVE-2019-11767?
No, phpBB version 3.2.6 is not affected by CVE-2019-11767.
4
What is the severity of CVE-2019-11767?
CVE-2019-11767 has a severity score of 5.8, which is considered medium.
5
How can I fix CVE-2019-11767?
To fix CVE-2019-11767, you should upgrade phpBB to version 3.2.6 or newer.