CVE-2019-16107: CSRF
Published Mar 11, 2020
·Updated
Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.
Affected Software
2 affected componentsFixes available
composer/phpbb/phpbb=3.2.7
3.2.8
phpBB phpbb=3.2.7
Event History
Mar 11, 2020
CVE Published
via MITRE·12:46 PM
Data Sourced
via MITRE·12:46 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:10 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-16107?
The severity of CVE-2019-16107 is medium with a CVSS score of 4.3.
2
How does CVE-2019-16107 affect phpBB?
CVE-2019-16107 affects phpBB version 3.2.7.
3
What vulnerability does CVE-2019-16107 have?
CVE-2019-16107 is a vulnerability that allows CSRF in deleting post attachments due to missing form token validation in phpBB 3.2.7.
4
How can I fix CVE-2019-16107?
To fix CVE-2019-16107, upgrade phpBB to a version that includes the necessary form token validation.
5
Where can I find more information about CVE-2019-16107?
You can find more information about CVE-2019-16107 on the phpBB community forums and the phpBB topic linked in the references.